DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.
| Software | From | Fixed in |
|---|---|---|
| daniel_barron / dansguardian | 2.2.8 | 2.2.8.x |
| daniel_barron / dansguardian | 2.2.4 | 2.2.4.x |
| daniel_barron / dansguardian | 2.8 | 2.8.x |
| daniel_barron / dansguardian | 2.6.1.5 | 2.6.1.5.x |
| daniel_barron / dansguardian | 2.2.9 | 2.2.9.x |
| daniel_barron / dansguardian | 2.7.3.1 | 2.7.3.1.x |
| daniel_barron / dansguardian | 2.2.6 | 2.2.6.x |
| daniel_barron / dansguardian | 2.2.7 | 2.2.7.x |
| daniel_barron / dansguardian | 2.2.7.1 | 2.2.7.1.x |
| daniel_barron / dansguardian | 2.4.5.1 | 2.4.5.1.x |
| daniel_barron / dansguardian | 2.2.9.1 | 2.2.9.1.x |
| daniel_barron / dansguardian | 2.2.10 | 2.2.10.x |
| daniel_barron / dansguardian | 2.2.5 | 2.2.5.x |