mirror of
https://github.com/Piwigo/Piwigo.git
synced 2026-03-28 17:42:57 +01:00
merge r6909 from branch 2.1 to trunk
bug 1850 fixed: strong check of $_GET['cat'] git-svn-id: http://piwigo.org/svn/trunk@6910 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
@@ -104,6 +104,8 @@ $page['where_clauses'] = array();
|
||||
// which category to filter on ?
|
||||
if (isset($_GET['cat']) and 0 != $_GET['cat'])
|
||||
{
|
||||
check_input_parameter('cat', $_GET, false, PATTERN_ID);
|
||||
|
||||
$page['where_clauses'][] =
|
||||
'category_id IN ('.implode(',', get_subcat_ids(array($_GET['cat']))).')';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user