Fix: Sanitize data 2

This commit is contained in:
Laurent Destailleur 2012-03-27 18:36:32 +02:00
parent 28cf1345e0
commit 0c225372d6

View File

@ -102,7 +102,7 @@ $time_start = time();
// MYSQL // MYSQL
if ($what == 'mysql') if ($what == 'mysql')
{ {
$cmddump=$_POST["mysqldump"]; $cmddump=GETPOST("mysqldump"); // Do not sanitize here with 'alpha', will be sanitize later by escapeshellarg
if ($cmddump) if ($cmddump)
{ {
dolibarr_set_const($db, 'SYSTEMTOOLS_MYSQLDUMP', $cmddump,'chaine',0,'',$conf->entity); dolibarr_set_const($db, 'SYSTEMTOOLS_MYSQLDUMP', $cmddump,'chaine',0,'',$conf->entity);
@ -265,7 +265,7 @@ if ($what == 'mysqlnobin')
// POSTGRESQL // POSTGRESQL
if ($what == 'postgresql') if ($what == 'postgresql')
{ {
$cmddump=$_POST["postgresqldump"]; $cmddump=GETPOST("postgresqldump"); // Do not sanitize here with 'alpha', will be sanitize later by escapeshellarg
if ($cmddump) if ($cmddump)
{ {
dolibarr_set_const($db, 'SYSTEMTOOLS_POSTGRESQLDUMP', $cmddump,'chaine',0,'',$conf->entity); dolibarr_set_const($db, 'SYSTEMTOOLS_POSTGRESQLDUMP', $cmddump,'chaine',0,'',$conf->entity);
@ -295,7 +295,7 @@ if ($what == 'postgresql')
if (GETPOST("drop")) $param.=" --add-drop-table"; if (GETPOST("drop")) $param.=" --add-drop-table";
if (! GETPOST("sql_data")) $param.=" -s"; if (! GETPOST("sql_data")) $param.=" -s";
} }
if ($_POST["sql_data"]) if (GETPOST("sql_data"))
{ {
if (! GETPOST("sql_structure")) $param.=" -a"; if (! GETPOST("sql_structure")) $param.=" -a";
if (GETPOST("showcolumns")) $param.=" -c"; if (GETPOST("showcolumns")) $param.=" -c";