X-Git-Url: http://git.cyclocoop.org/?p=ptitvelo%2Fweb%2Fwww.git;a=blobdiff_plain;f=www%2Fconfig%2Fecran_securite.php;h=36b00446bc4c9162d14b89b21cb07feb3dbcc0e0;hp=7e6ec1c5f99b555757532ffb67487511fb1c5d3a;hb=e847eea4a82a7396dd0abf860f9b30d654f38629;hpb=d686c3e22e97dd46ef42bcd0f138c65083f8f232 diff --git a/www/config/ecran_securite.php b/www/config/ecran_securite.php index 7e6ec1c..36b0044 100644 --- a/www/config/ecran_securite.php +++ b/www/config/ecran_securite.php @@ -5,7 +5,7 @@ * ------------------ */ -define('_ECRAN_SECURITE', '1.1.8'); // 2013-08-29 +define('_ECRAN_SECURITE', '1.1.9'); // 2014-03-13 /* * Documentation : http://www.spip.net/fr_article4200.html @@ -254,13 +254,12 @@ if (isset($_REQUEST['connect']) AND // cas qui permettent de sortir d'un commentaire PHP (strpos($_REQUEST['connect'], "?")!==false + OR strpos($_REQUEST['connect'], "<")!==false OR strpos($_REQUEST['connect'], ">")!==false OR strpos($_REQUEST['connect'], "\n")!==false OR strpos($_REQUEST['connect'], "\r")!==false) ) { - $_REQUEST['connect'] = str_replace(array("?", ">", "\r", "\n"), "", $_REQUEST['connect']); - if (isset($_GET['connect'])) $_GET['connect'] = $_REQUEST['connect']; - if (isset($_POST['connect'])) $_POST['connect'] = $_REQUEST['connect']; + $ecran_securite_raison = "malformed connect argument"; } /* @@ -317,4 +316,4 @@ if ( } -?> +?> \ No newline at end of file