mirror of
https://github.com/e107inc/e107.git
synced 2025-08-01 20:30:39 +02:00
Update phpinfo.php
This commit is contained in:
@@ -15,6 +15,9 @@ if(!getperms("0"))
|
|||||||
e107::redirect('admin');
|
e107::redirect('admin');
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
e107::coreLan('phpinfo', true);
|
||||||
|
|
||||||
$e_sub_cat = 'phpinfo';
|
$e_sub_cat = 'phpinfo';
|
||||||
require_once("auth.php");
|
require_once("auth.php");
|
||||||
|
|
||||||
@@ -38,11 +41,11 @@ $phpinfo = preg_replace('/<table[^>]*>/i', '<table class="table table-striped ad
|
|||||||
$mes = e107::getMessage();
|
$mes = e107::getMessage();
|
||||||
|
|
||||||
$security_risks = array(
|
$security_risks = array(
|
||||||
"allow_url_fopen" => 'If you have Curl enabled, you should consider disabling this feature.',
|
"allow_url_fopen" => PHP_LAN_1,
|
||||||
"allow_url_include" => 'This is a security risk and is not needed by e107.',
|
"allow_url_include" => PHP_LAN_2,
|
||||||
"display_errors" => 'On a production server, it is better to disable the displaying of errors in the browser.',
|
"display_errors" => PHP_LAN_3,
|
||||||
"expose_php" => 'Disabling this will hide your PHP version from browsers.',
|
"expose_php" => PHP_LAN_4,
|
||||||
"register_globals" => 'This is a security risk and should be disabled.'
|
"register_globals" => PHP_LAN_5
|
||||||
);
|
);
|
||||||
|
|
||||||
foreach($security_risks as $risk=>$diz)
|
foreach($security_risks as $risk=>$diz)
|
||||||
@@ -62,7 +65,7 @@ $security_risks = array(
|
|||||||
{
|
{
|
||||||
if(!is_writable($sessionSavePath) && $sessionSaveMethod === 'files')
|
if(!is_writable($sessionSavePath) && $sessionSaveMethod === 'files')
|
||||||
{
|
{
|
||||||
$mes->addError("<b>session.save_path</b> is not writable! That can cause major issues with your site.");
|
$mes->addError("<b>session.save_path</b> ".PHP_LAN_6);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user