svn: /web/php/trunk/include/ do-download.inc langchooser.inc
| From: | Rasmus Lerdorf | Date: | Fri, 21 Jan 2011 15:28:33 +0000 |
| Subject: | svn: /web/php/trunk/include/ do-download.inc langchooser.inc | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-10464@lists.php.net to get a copy of this message | ||
rasmus Fri, 21 Jan 2011 15:28:33 +0000
Revision: http://svn.php.net/viewvc?view=revision&revision=307654
Log:
Fix xss problems
Changed paths:
U web/php/trunk/include/do-download.inc
U web/php/trunk/include/langchooser.inc
Modified: web/php/trunk/include/do-download.inc
===================================================================
--- web/php/trunk/include/do-download.inc 2011-01-21 13:48:25 UTC (rev 307653)
+++ web/php/trunk/include/do-download.inc 2011-01-21 15:28:33 UTC (rev 307654)
@@ -32,7 +32,7 @@
// If user comes from a mirror selection page, provide a backlink
if (isset($_SERVER['HTTP_REFERER']) &&
preg_match("!/from/a/mirror$!", $_SERVER['HTTP_REFERER'])) {
- $moreinfo = ", or <a
href=\"{$_SERVER['HTTP_REFERER']}\">reconsider your mirror
selection</a>";
+ $moreinfo = ", or <a
href=\"".htmlspecialchars($_SERVER['HTTP_REFERER'],ENT_QUOTES,'UTF-8')."\">reconsider
your mirror selection</a>";
} else { $moreinfo = ""; }
// An executable was requested (temp fix for rsync change)
Modified: web/php/trunk/include/langchooser.inc
===================================================================
--- web/php/trunk/include/langchooser.inc 2011-01-21 13:48:25 UTC (rev 307653)
+++ web/php/trunk/include/langchooser.inc 2011-01-21 15:28:33 UTC (rev 307654)
@@ -31,7 +31,7 @@
*/
// Default STRIPPED_URI
-$_SERVER['STRIPPED_URI'] = $_SERVER['REQUEST_URI'];
+$_SERVER['STRIPPED_URI'] = htmlspecialchars($_SERVER['REQUEST_URI'],
ENT_QUOTES, 'UTF-8');
// The code is encapsulated in a function,
// so the variable namespace is not polluted
@@ -51,14 +51,14 @@
// Specified for the request (GET/POST parameter)
if (!empty($_REQUEST['lang'])) {
- $explicitly_specified = language_add($_REQUEST['lang'], $languages);
+ $explicitly_specified = language_add(htmlspecialchars($_REQUEST['lang'],
ENT_QUOTES, 'UTF-8'), $languages);
// Set the language in a cookie for a year
mirror_setcookie("LAST_LANG", $explicitly_specified, 60*60*24*365);
}
// Specified in a shortcut URL (eg. /en/echo or /pt_br/echo)
- if (preg_match("!^/(\\w{2}(_\\w{2})?)/!", $_SERVER['REQUEST_URI'], $flang))
{
+ if (preg_match("!^/(\\w{2}(_\\w{2})?)/!",
htmlspecialchars($_SERVER['REQUEST_URI'],ENT_QUOTES, 'UTF-8'), $flang)) {
// Put language into preference list
$rlang = language_add($flang[1], $languages);
@@ -70,13 +70,13 @@
// Drop out langauge specification from URL, as this is already handled
$_SERVER['STRIPPED_URI'] = preg_replace(
- "!^/$flang[1]/!", "/", $_SERVER['REQUEST_URI']
+ "!^/$flang[1]/!", "/",
htmlspecialchars($_SERVER['REQUEST_URI'], ENT_QUOTES, 'UTF-8')
);
}
// Specified in a manual URL (eg. manual/en/ or manual/pt_br/)
- if (preg_match("!^/manual/(\\w{2}(_\\w{2})?)(/|$)!",
$_SERVER['REQUEST_URI'], $flang)) {
+ if (preg_match("!^/manual/(\\w{2}(_\\w{2})?)(/|$)!",
htmlspecialchars($_SERVER['REQUEST_URI'], ENT_QUOTES, 'UTF-8'), $flang)) {
$flang = language_add($flang[1], $languages);