Fix: A local file inclusion vulnerability can be exploited to include arbitrary files.
This commit is contained in:
parent
5b4ec9e316
commit
77f44797bb
@ -673,7 +673,6 @@ if (! defined('NOLOGIN'))
|
|||||||
else $conf->use_javascript_ajax=0;
|
else $conf->use_javascript_ajax=0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
if (! defined('NOREQUIRETRAN'))
|
if (! defined('NOREQUIRETRAN'))
|
||||||
{
|
{
|
||||||
if (! GETPOST('lang')) // If language was not forced on URL
|
if (! GETPOST('lang')) // If language was not forced on URL
|
||||||
@ -691,14 +690,14 @@ if (! defined('NOREQUIRETRAN'))
|
|||||||
}
|
}
|
||||||
else // If language was forced on URL
|
else // If language was forced on URL
|
||||||
{
|
{
|
||||||
$langs->setDefaultLang(GETPOST('lang'));
|
$langs->setDefaultLang(GETPOST('lang','alpha',1));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Case forcing style from url
|
// Case forcing style from url
|
||||||
if (GETPOST('theme'))
|
if (GETPOST('theme'))
|
||||||
{
|
{
|
||||||
$conf->theme=GETPOST('theme');
|
$conf->theme=GETPOST('theme','alpha',1);
|
||||||
$conf->css = "/theme/".$conf->theme."/style.css.php";
|
$conf->css = "/theme/".$conf->theme."/style.css.php";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user