Closed (fixed)
Project:
Security Review
Version:
6.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
18 Jun 2012 at 21:59 UTC
Updated:
4 Dec 2012 at 23:50 UTC
Jump to comment: Most recent file
Comments
Comment #1
gregglesand patch.
If this works for you then I can re-roll #1645750: identify private files as a non-dangerous writable dir to apply after this and use the extra
'./' .Comment #2
crimsondryad commentedWe are running multisite installs and we also use a custom directory for files ( ie, not /sites/default/files ) in the Drupal webroot ( ie /media-assets ). In this case, it seems like not only should the patch check /sites/default/files, but also whatever the Drupal files path is defined as in Configuration > File System
Comment #3
coltrane@crimsondryad it does use the variable that contains the path set at Admin > Configuration > File System.
Patch works well, thanks greggles! http://drupalcode.org/project/security_review.git/commit/aa1422d
Comment #4
coltraneRe-opening to port to D6.
Comment #5
coltraneFixed in 6. http://drupalcode.org/project/security_review.git/commit/604f2b8