mirror of
https://github.com/Lastorder-DC/rhymix.git
synced 2026-05-09 12:02:24 +09:00
XSS, Webshell defence
git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.3.2@12278 201d5d3c-b55e-5fd7-737f-ddc643e51545
This commit is contained in:
parent
fdcafe536e
commit
0c0604d24d
2 changed files with 4 additions and 1 deletions
|
|
@ -59,6 +59,9 @@
|
||||||
Context::set('status_name_list', $statusNameList);
|
Context::set('status_name_list', $statusNameList);
|
||||||
Context::set('page_navigation', $output->page_navigation);
|
Context::set('page_navigation', $output->page_navigation);
|
||||||
|
|
||||||
|
$oSecurity = new Security();
|
||||||
|
$oSecurity->encodeHTML('document_list..variables.');
|
||||||
|
|
||||||
// set a search option used in the template
|
// set a search option used in the template
|
||||||
$count_search_option = count($this->search_option);
|
$count_search_option = count($this->search_option);
|
||||||
for($i=0;$i<$count_search_option;$i++) {
|
for($i=0;$i<$count_search_option;$i++) {
|
||||||
|
|
|
||||||
|
|
@ -150,7 +150,7 @@
|
||||||
$buff = '<?php if(!defined("__ZBXE__")) exit();'."\n";
|
$buff = '<?php if(!defined("__ZBXE__")) exit();'."\n";
|
||||||
foreach($ftp_info as $key => $val) {
|
foreach($ftp_info as $key => $val) {
|
||||||
if(!$val) continue;
|
if(!$val) continue;
|
||||||
if(preg_match('/(<\?|<\?php|\?>)/xsm', preg_replace('/\s/', '', $val)))
|
if(preg_match('/(<\?|<\?php|\?>|fputs|fopen|fwrite|fgets|fread|\/\*|\*\/|chr\()/xsm', preg_replace('/\s/', '', $val)))
|
||||||
{
|
{
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue