Files
danbooru/test/unit
evazion 99221e4028 Downloads::File: fix SSRF attack when fetching remote size (#2498).
Fixes the banned IP check not being applied when fetching the remote
file size. This allowed one to trick Danbooru into sending HEAD requests
to private IPs:

  http://danbooru.donmai.us/uploads/new?url=http://127.0.0.1/test.jpg
2018-09-18 12:16:27 -05:00
..
2018-05-09 11:59:51 -07:00
2018-05-15 14:19:45 -07:00
2018-04-06 18:09:57 -07:00
2018-05-09 11:59:51 -07:00
2018-09-04 13:38:09 -07:00
2018-08-24 12:10:51 -07:00
2018-04-06 18:09:57 -07:00
2018-06-20 11:11:46 -07:00
2018-05-15 14:19:45 -07:00