Fix: security

This commit is contained in:
Laurent Destailleur 2014-05-28 19:38:30 +02:00
parent baa573435b
commit 1f8c35b70b

View File

@ -54,16 +54,23 @@ print '</div>';
print '<div class="principal">';
if ( $_GET['menu'] )
$page=GETPOST('menu','alpha');
if (in_array(
$page,
array(
'deconnexion',
'index','index_verif','facturation','facturation_verif','facturation_dhtml',
'validation','validation_ok','validation_ticket','validation_verif',
)
))
{
include $_GET['menu'].'.php';
include $page.'.php';
}
else
{
include 'facturation.php';
dol_print_error('','menu param '.$page.' is not inside allowed list');
}
print '</div>';
$_SESSION['serObjFacturation'] = serialize($obj_facturation);