From d2c7671d931c0e1eb12437924d1b37590a6185ee Mon Sep 17 00:00:00 2001 From: plegall Date: Sat, 7 Apr 2012 21:02:56 +0000 Subject: merge r13957 from branch 2.3 to trunk bug 2611 fixed: check $_GET['section'] input parameter git-svn-id: http://piwigo.org/svn/trunk@13958 68402e56-0260-453c-a942-63ccdbb3a9ee --- admin/configuration.php | 3 +++ 1 file changed, 3 insertions(+) diff --git a/admin/configuration.php b/admin/configuration.php index 7ab175c53..2258dab99 100644 --- a/admin/configuration.php +++ b/admin/configuration.php @@ -36,6 +36,9 @@ include_once(PHPWG_ROOT_PATH.'admin/include/tabsheet.class.php'); check_status(ACCESS_ADMINISTRATOR); //-------------------------------------------------------- sections definitions + +check_input_parameter('section', $_GET, false, '/^[a-z]+$/i'); + if (!isset($_GET['section'])) { $page['section'] = 'main'; -- cgit v1.2.3