diff --git a/var/www/modules/showpaste/Flask_showpaste.py b/var/www/modules/showpaste/Flask_showpaste.py index 2d856a96..9ea5f22a 100644 --- a/var/www/modules/showpaste/Flask_showpaste.py +++ b/var/www/modules/showpaste/Flask_showpaste.py @@ -258,7 +258,7 @@ def show_item_min(requested_path , content_range=0): relative_path = requested_path requested_path = os.path.join(PASTES_FOLDER, requested_path) else: - relative_path = requested_path.replace(PASTES_FOLDER, '', 1)[1:] + relative_path = requested_path.replace(PASTES_FOLDER, '', 1) # remove old full path #requested_path = requested_path.replace(PASTES_FOLDER, '') # escape directory transversal