secure commonly used filename-variable against url manipulation
Signed-off-by: Michael Kaufmann <d00p@froxlor.org>
This commit is contained in:
@@ -103,7 +103,7 @@ unset($_);
|
|||||||
unset($value);
|
unset($value);
|
||||||
unset($key);
|
unset($key);
|
||||||
|
|
||||||
$filename = htmlentities(basename($_SERVER['PHP_SELF']));
|
$filename = htmlentities(basename($_SERVER['SCRIPT_NAME']));
|
||||||
|
|
||||||
// check whether the userdata file exists
|
// check whether the userdata file exists
|
||||||
if (! file_exists(\Froxlor\Froxlor::getInstallDir() . '/lib/userdata.inc.php')) {
|
if (! file_exists(\Froxlor\Froxlor::getInstallDir() . '/lib/userdata.inc.php')) {
|
||||||
|
|||||||
Reference in New Issue
Block a user