com web/php: Un-taint the base tag with "./" things :): include/site.inc
| From: | Hannes Magnusson | Date: | Thu, 21 Nov 2013 18:00:58 +0000 |
| Subject: | com web/php: Un-taint the base tag with "./" things :): include/site.inc | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-17155@lists.php.net to get a copy of this message | ||
Commit: 0bc5a56ab751f5a6c98f1ebca4df8964207e99ae
Author: Hannes Magnusson <bjori@mongodb.com> Thu, 21 Nov 2013 10:00:58 -0800
Parents: 22417cdf3bd134774a3c738d94405207d4367a06
Branches: master
Link: http://git.php.net/?p=web/php.git;a=commitdiff;h=0bc5a56ab751f5a6c98f1ebca4df8964207e99ae
Log:
Un-taint the base tag with "./" things :)
Changed paths:
M include/site.inc
Diff:
diff --git a/include/site.inc b/include/site.inc
index 3137fc8..1639ddd 100644
--- a/include/site.inc
+++ b/include/site.inc
@@ -553,7 +553,10 @@ if (isset($_SERVER['MIRROR_STATS'])) {
// Provide base href information to make relative links on
// shortcut URL accessed pages work without redirection
if (isset($_SERVER['BASE_PAGE'])) {
- $dirname = dirname($_SERVER['BASE_PAGE']);
- $_SERVER['BASE_HREF'] = $MYSITE . $dirname . "/";
+ $dirname = dirname($_SERVER['BASE_PAGE']) . "/";
+ if ($dirname == "./") {
+ $dirname = "";
+ }
+ $_SERVER['BASE_HREF'] = $MYSITE . $dirname;
} else { unset($_SERVER['BASE_HREF']); }