merge r30563 from trunk to branch 2.6

bug 3178 fixed, in_array check is not reliable when you compare string (user input) and numeric values


git-svn-id: http://piwigo.org/svn/branches/2.6@30567 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
plegall
2014-11-21 12:20:49 +00:00
parent 34c7adb96d
commit 2fce0ab1d0
+1
View File
@@ -39,6 +39,7 @@ function rate_picture($image_id, $rate)
if (!isset($rate)
or !$conf['rate']
or !preg_match('/^[0-9]+$/', $rate)
or !in_array($rate, $conf['rate_items']))
{
return false;