Explorar o código

Merge pull request #116 from logig/master

Security enhancements for WordPress upload directory
lj2007331 %!s(int64=7) %!d(string=hai) anos
pai
achega
e9bf418ad7
Modificáronse 1 ficheiros con 3 adicións e 0 borrados
  1. 3 0
      config/wordpress.conf

+ 3 - 0
config/wordpress.conf

@@ -2,3 +2,6 @@ location / {
   try_files $uri $uri/ /index.php?$args;
   try_files $uri $uri/ /index.php?$args;
 }
 }
 rewrite /wp-admin$ $scheme://$host$uri/ permanent;
 rewrite /wp-admin$ $scheme://$host$uri/ permanent;
+location ~* ^/wp-content/uploads/.*\.php$ {
+  deny all;
+}