Fix: A local file inclusion vulnerability can be exploited to include arbitrary files.

This commit is contained in:
Laurent Destailleur 2011-04-27 17:05:05 +00:00
parent 5b4ec9e316
commit 77f44797bb

View File

@ -673,7 +673,6 @@ if (! defined('NOLOGIN'))
else $conf->use_javascript_ajax=0; else $conf->use_javascript_ajax=0;
} }
if (! defined('NOREQUIRETRAN')) if (! defined('NOREQUIRETRAN'))
{ {
if (! GETPOST('lang')) // If language was not forced on URL if (! GETPOST('lang')) // If language was not forced on URL
@ -691,14 +690,14 @@ if (! defined('NOREQUIRETRAN'))
} }
else // If language was forced on URL else // If language was forced on URL
{ {
$langs->setDefaultLang(GETPOST('lang')); $langs->setDefaultLang(GETPOST('lang','alpha',1));
} }
} }
// Case forcing style from url // Case forcing style from url
if (GETPOST('theme')) if (GETPOST('theme'))
{ {
$conf->theme=GETPOST('theme'); $conf->theme=GETPOST('theme','alpha',1);
$conf->css = "/theme/".$conf->theme."/style.css.php"; $conf->css = "/theme/".$conf->theme."/style.css.php";
} }