root path in test browser not enforced

Description

It is possible to view the contents of directories above the root path by passing ../ or ..\ as part of your path in the URL.

http://127.0.0.1:49616/test-browser/index.cfm?path=/../../../
or
http://127.0.0.1:49616/test-browser/index.cfm?path=/..%5C..%5C..%5C

Assignee

Brad Wood

Reporter

Brad Wood

Labels

None

Fix versions

Priority

Major
Configure