cvs: php-gcov-web(SOC06) /www viewer.php
| From: | Nuno Lopes | Date: | Sun, 10 Sep 2006 16:57:12 +0000 |
| Subject: | cvs: php-gcov-web(SOC06) /www viewer.php | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-32448@lists.php.net to get a copy of this message | ||
nlopess Sun Sep 10 16:57:12 2006 UTC
Modified files: (Branch: SOC06)
/php-gcov-web/www viewer.php
Log:
fix possible security problem with bad version tags
http://cvs.php.net/viewvc.cgi/php-gcov-web/www/viewer.php?r1=1.1.2.14&r2=1.1.2.15&diff_format=u
Index: php-gcov-web/www/viewer.php
diff -u php-gcov-web/www/viewer.php:1.1.2.14 php-gcov-web/www/viewer.php:1.1.2.15
--- php-gcov-web/www/viewer.php:1.1.2.14 Sun Sep 10 15:28:52 2006
+++ php-gcov-web/www/viewer.php Sun Sep 10 16:57:12 2006
@@ -18,7 +18,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: viewer.php,v 1.1.2.14 2006/09/10 15:28:52 nlopess Exp $ */
+/* $Id: viewer.php,v 1.1.2.15 2006/09/10 16:57:12 nlopess Exp $ */
// Name: GCOV Viewer page
// Desc: page for view PHP version information such as code coverage
@@ -35,7 +35,7 @@
$fileroot = ''; // base directory for including external files (used for external builds)
$file = isset($_REQUEST['file']) ? basename($_REQUEST['file']) :
'';
-$version = isset($_REQUEST['version']) ? $_REQUEST['version'] : '';
+$version = isset($_REQUEST['version']) &&
isset($appvars['site']['tags'][$_REQUEST['version']]) ?
$_REQUEST['version'] : '';
$mode = isset($_REQUEST['mode']) ? $_REQUEST['mode'] : '';
@@ -113,9 +113,7 @@
}
$appvars['site']['func'] = $func;
-// Ensure the version specified is valid (todo: more security required?)
-// note: !== false is required since PHP_4.4.1 has the 0th place
-if((array_search($version, $appvars['site']['tags']) !== false) || ($func ==
'search'))
+if($version || $func === 'search')
{
$appvars['site']['mytag'] = $version;