Changeset 21
- Timestamp:
- Mar 1, 2010, 11:22:47 PM (15 years ago)
- Location:
- trunk
- Files:
-
- 1 deleted
- 4 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/admin/admin.php
r15 r21 71 71 72 72 foreach ($_GET as $sec_key => $secvalue) { 73 if (( eregi("<[^>]*script*\"?[^>]*>",$secvalue)) ||74 ( eregi("<[^>]*object*\"?[^>]*>", $secvalue)) ||75 ( eregi("<[^>]*iframe*\"?[^>]*>", $secvalue)) ||76 ( eregi("<[^>]*applet*\"?[^>]*>", $secvalue)) ||77 ( eregi("<[^>]*meta*\"?[^>]*>", $secvalue)) ||78 ( eregi("<[^>]*style*\"?[^>]*>", $secvalue)) ||79 ( eregi("<[^>]*form*\"?[^>]*>", $secvalue)) ||80 ( eregi("<[^>]*img*\"?[^>]*>", $secvalue)) ||81 ( eregi("<[^>]*onmouseover*\"?[^>]*>", $secvalue)) ||82 ( eregi("<[^>]*body*\"?[^>]*>", $secvalue)) ||83 ( eregi("\([^>]*\"?[^)]*\)", $secvalue)) ||84 ( eregi("\"", $secvalue)) ||85 ( eregi("inside_mod", $sec_key))) {73 if ((preg_match("/<[^>]*script*\"?[^>]*>/i",$secvalue)) || 74 (preg_match("/<[^>]*object*\"?[^>]*>/i", $secvalue)) || 75 (preg_match("/<[^>]*iframe*\"?[^>]*>/i", $secvalue)) || 76 (preg_match("/<[^>]*applet*\"?[^>]*>/i", $secvalue)) || 77 (preg_match("/<[^>]*meta*\"?[^>]*>/i", $secvalue)) || 78 (preg_match("/<[^>]*style*\"?[^>]*>/i", $secvalue)) || 79 (preg_match("/<[^>]*form*\"?[^>]*>/i", $secvalue)) || 80 (preg_match("/<[^>]*img*\"?[^>]*>/i", $secvalue)) || 81 (preg_match("/<[^>]*onmouseover*\"?[^>]*>/i", $secvalue)) || 82 (preg_match("/<[^>]*body*\"?[^>]*>/i", $secvalue)) || 83 (preg_match("/\([^>]*\"?[^)]*\)/", $secvalue)) || 84 (preg_match("/\"/", $secvalue)) || 85 (preg_match("/inside_mod/i", $sec_key))) { 86 86 die ("Operazione non consentita"); 87 87 } … … 89 89 90 90 foreach ($_POST as $secvalue) { 91 if (( eregi("<[^>]*onmouseover*\"?[^>]*>", $secvalue)) || (eregi("<[^>]script*\"?[^>]*>", $secvalue)) || (eregi("<[^>]*body*\"?[^>]*>", $secvalue)) || (eregi("<[^>]style*\"?[^>]*>", $secvalue))) {91 if ((preg_match("/<[^>]*onmouseover*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]script*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]*body*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]style*\"?[^>]*>/i", $secvalue))) { 92 92 die ('Operazione non consentita'); 93 93 } … … 124 124 $dbi=mysql_connect($dbhost, $dbuname, $dbpass) or die("Connessione non riuscita: " . mysql_error()); 125 125 mysql_select_db($dbname)or die("Connessione non riuscita:" . mysql_error()); 126 mysql_set_charset('utf8', $dbi); 126 # mysql_set_charset('utf8', $dbi); 127 mysql_query("SET NAMES 'utf8'", $dbi); 127 128 //---10/05/2009 gestione consultazione predefinita 128 129 $res_config = mysql_query("select * from ".$prefix."_config ",$dbi); … … 161 162 if (strlen($aid)>25 ) { die ("Nome utente troppo lungo: $aid"); } 162 163 if (!isset($param['id_ses']) or $param['id_ses'] != session_id()) logout(); 163 if ( ereg(" ", $aid)) { die ("Gli spazi non sono ammessi nel nome utente: $aid"); }164 if (strstr( $aid," ")) { die ("Gli spazi non sono ammessi nel nome utente: $aid"); } 164 165 if (isset($_SESSION['aid'])){ 165 166 logout();//se hai gia' una sessione aperta non puoi postare 'aid' -
trunk/client/modules/Elezioni/grafici.php
r2 r21 442 442 //$descrizione=taglio(4,$descrizione); 443 443 444 $gruppo[$i]= utf8_encode(substr($descrizione,0,21));445 $gruppos[$e]= utf8_encode(substr($descrizione,0,21)); //flash444 $gruppo[$i]=(substr($descrizione,0,21)); 445 $gruppos[$e]=(substr($descrizione,0,21)); //flash 446 446 447 447 -
trunk/client/modules/Elezioni/grafici/affluenze_graf.php
r2 r21 10 10 include ("jpgraph.php"); 11 11 include ("jpgraph_pie.php"); 12 define("CURFONT1",FF_DV_SANSSERIF); 12 13 13 14 $e=$_GET['e'];$f=$_GET['f'];$e1=$_GET['e1'];$f1=$_GET['f1']; … … 22 23 23 24 $graph->title->Set($titolo); 24 $graph->title->SetFont( FF_FONT1,FS_BOLD);25 $graph->title->SetFont(CURFONT1,FS_BOLD); 25 26 $graph ->legend->Pos( 0.02,0.85,"left" ,"center"); 26 27 $graph->SetBackgroundImage("../images/logo.jpg",BGIMG_COPY); -
trunk/client/modules/Elezioni/grafici/jpg-config.inc.php
r2 r21 31 31 // MBTTF_DIR /usr/share/fonts/ja/TrueType/ 32 32 // 33 define("TTF_DIR","/usr/share/fonts/truetype/ttf-dejavu/"); 33 34 // WINDOWS: 34 35 // CACHE_DIR $SERVER_TEMP/jpgraph_cache/
Note:
See TracChangeset
for help on using the changeset viewer.