cvs: phpweb / results.php
| From: | Hannes Magnusson | Date: | Wed, 19 Mar 2008 11:47:46 +0000 |
| Subject: | cvs: phpweb / results.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-1318@lists.php.net to get a copy of this message | ||
bjori Wed Mar 19 11:47:46 2008 UTC
Modified files:
/phpweb results.php
Log:
Fixed bug#44030 (Lack of validation of input parameters)
http://cvs.php.net/viewvc.cgi/phpweb/results.php?r1=1.32&r2=1.33&diff_format=u
Index: phpweb/results.php
diff -u phpweb/results.php:1.32 phpweb/results.php:1.33
--- phpweb/results.php:1.32 Wed Mar 19 11:31:33 2008
+++ phpweb/results.php Wed Mar 19 11:47:46 2008
@@ -1,9 +1,26 @@
<?php
-// $Id: results.php,v 1.32 2008/03/19 11:31:33 bjori Exp $
+// $Id: results.php,v 1.33 2008/03/19 11:47:46 bjori Exp $
$_SERVER['BASE_PAGE'] = 'results.php';
include $_SERVER['DOCUMENT_ROOT'] . '/include/prepend.inc';
#include $_SERVER['DOCUMENT_ROOT'] . '/include/loadavg.inc';
+function exit_with_pretty_error($title, $header, $msg) {
+ if ($title) {
+ site_header($title);
+ }
+ echo '<h2>' .$header. '</h2>';
+ echo '<p>' .$msg. '</p>';
+ site_footer();
+ exit;
+}
+
+if (!isset($_GET['q']) || (!is_string($_GET['q']) ||
strlen($_GET['q']) < 3)) {
+ exit_with_pretty_error("Search results", "Empty query", "You need to
specify what you want to search for, 3chars at least");
+}
+if (!isset($_GET['l']) || !is_string($_GET['l'])) {
+ $_GET['l'] = null;
+}
+
// Prepare data for search
if ($MQ) {
$q = stripslashes($_GET['q']); //query
@@ -18,8 +35,8 @@
$q = urlencode($q);
$l = urlencode($l);
-$s = (isset($_GET['start'])&&$_GET['start']!=0) ?
(int)$_GET['start'] : 1;
-$profile = isset($_GET['p']) ? $_GET['p'] : 'all';
+$s = (isset($_GET['start']) && is_numeric($_GET['start']) &&
$_GET['start']!=0) ? (int)$_GET['start'] : 1;
+$profile = (isset($_GET['p']) && is_string($_GET['p'])) ?
$_GET['p'] : 'all';
$per_page = 10;
$valid_profiles = array('all', 'local', 'manual', 'news',
'bugs', 'pear', 'pecl', 'talks');
@@ -59,15 +76,12 @@
site_header('Search results');
if (!is_array($res)) {
- echo '<h2>Internal error, please try later</h2>';
- site_footer();
- exit;
+ exit_with_pretty_error(null, 'Internal error', 'Please try again later');
}
// No results for query
if ($res['ResultSet']['totalResultsAvailable'] == 0) {
- echo '<h2>No pages matched your query</h2>';
- site_footer();
+ exit_with_pretty_error(null, 'No matches', 'No pages matched your query');
exit;
}