cvs: phpweb / results.php

From: Date: Wed, 19 Mar 2008 11:47:46 +0000
Subject: cvs: phpweb / results.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-1318@lists.php.net to get a copy of this message
bjori Wed Mar 19 11:47:46 2008 UTC Modified files: /phpweb results.php Log: Fixed bug#44030 (Lack of validation of input parameters) http://cvs.php.net/viewvc.cgi/phpweb/results.php?r1=1.32&r2=1.33&diff_format=u Index: phpweb/results.php diff -u phpweb/results.php:1.32 phpweb/results.php:1.33 --- phpweb/results.php:1.32 Wed Mar 19 11:31:33 2008 +++ phpweb/results.php Wed Mar 19 11:47:46 2008 @@ -1,9 +1,26 @@ <?php -// $Id: results.php,v 1.32 2008/03/19 11:31:33 bjori Exp $ +// $Id: results.php,v 1.33 2008/03/19 11:47:46 bjori Exp $ $_SERVER['BASE_PAGE'] = 'results.php'; include $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc'; #include $_SERVER['DOCUMENT_ROOT'] . '/include/loadavg.inc'; +function exit_with_pretty_error($title, $header, $msg) { + if ($title) { + site_header($title); + } + echo '<h2>' .$header. '</h2>'; + echo '<p>' .$msg. '</p>'; + site_footer(); + exit; +} + +if (!isset($_GET['q']) || (!is_string($_GET['q']) || strlen($_GET['q']) < 3)) { + exit_with_pretty_error("Search results", "Empty query", "You need to specify what you want to search for, 3chars at least"); +} +if (!isset($_GET['l']) || !is_string($_GET['l'])) { + $_GET['l'] = null; +} + // Prepare data for search if ($MQ) { $q = stripslashes($_GET['q']); //query @@ -18,8 +35,8 @@ $q = urlencode($q); $l = urlencode($l); -$s = (isset($_GET['start'])&&$_GET['start']!=0) ? (int)$_GET['start'] : 1; -$profile = isset($_GET['p']) ? $_GET['p'] : 'all'; +$s = (isset($_GET['start']) && is_numeric($_GET['start']) && $_GET['start']!=0) ? (int)$_GET['start'] : 1; +$profile = (isset($_GET['p']) && is_string($_GET['p'])) ? $_GET['p'] : 'all'; $per_page = 10; $valid_profiles = array('all', 'local', 'manual', 'news', 'bugs', 'pear', 'pecl', 'talks'); @@ -59,15 +76,12 @@ site_header('Search results'); if (!is_array($res)) { - echo '<h2>Internal error, please try later</h2>'; - site_footer(); - exit; + exit_with_pretty_error(null, 'Internal error', 'Please try again later'); } // No results for query if ($res['ResultSet']['totalResultsAvailable'] == 0) { - echo '<h2>No pages matched your query</h2>'; - site_footer(); + exit_with_pretty_error(null, 'No matches', 'No pages matched your query'); exit; }

« previous php.webmaster (#1318) next »