Changeset 344 for trunk/admin/admin.php
- Timestamp:
- Dec 1, 2020, 8:25:00 PM (4 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/admin/admin.php
r336 r344 45 45 46 46 $param=strtolower($_SERVER['REQUEST_METHOD']) == 'get' ? $_GET : $_POST; 47 if (isset($param['aid'])) get_magic_quotes_gpc() ? $aid=$param['aid']:$aid=addslashes($param['aid']);48 if (isset($param['pwd'])) get_magic_quotes_gpc() ? $pwd2=$param['pwd']:$pwd2=addslashes($param['pwd']);47 if (isset($param['aid'])) $aid=addslashes($param['aid']); else $aid=''; 48 if (isset($param['pwd'])) $pwd2=addslashes($param['pwd']); else $pwd2=''; 49 49 // Additional security (Union, CLike, XSS) 50 50 … … 399 399 400 400 #echo "op:".$param['op']." -- aid:".$_SESSION['aid']."remote:".$_SESSION['remote']."REMOTE:".$_SERVER['REMOTE_ADDR']; 401 if (isset($param['op'])) get_magic_quotes_gpc() ? $op=$param['op']:$op=addslashes($param['op']); else $op='ele';401 if (isset($param['op'])) $op=addslashes($param['op']); else $op='ele'; 402 402 //if (isset($param['op'])) $op=$param['op']; else $op='ele'; 403 403 if (isset($_SESSION['aid']) AND $_SESSION['remote']==$_SERVER['REMOTE_ADDR']) {
Note:
See TracChangeset
for help on using the changeset viewer.