mirror of
https://github.com/Piwigo/Piwigo.git
synced 2026-08-06 08:43:31 +02:00
bug 1849 fixed: protect $_GET keys against SQL injections before parsing URL.
git-svn-id: http://piwigo.org/svn/branches/2.1@6905 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
@@ -61,6 +61,10 @@ else
|
||||
$rewritten = $key;
|
||||
break;
|
||||
}
|
||||
|
||||
// the $_GET keys are not protected in include/common.inc.php, only the values
|
||||
$rewritten = pwg_db_real_escape_string($rewritten);
|
||||
|
||||
$page['root_path'] = PHPWG_ROOT_PATH;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user