mirror of
https://github.com/e107inc/e107.git
synced 2025-08-08 07:36:32 +02:00
Fixes #688 - filter query.
This commit is contained in:
@@ -2817,7 +2817,15 @@ class e107
|
|||||||
$input = preg_replace("/(\[code\])(.*?)(\[\/code\])/is","",$input);
|
$input = preg_replace("/(\[code\])(.*?)(\[\/code\])/is","",$input);
|
||||||
}
|
}
|
||||||
|
|
||||||
$regex = "/(document\.location|document\.write|base64_decode|chr|php_uname|fwrite|fopen|fputs|passthru|popen|proc_open|shell_exec|exec|proc_nice|proc_terminate|proc_get_status|proc_close|pfsockopen|apache_child_terminate|posix_kill|posix_mkfifo|posix_setpgid|posix_setsid|posix_setuid|phpinfo) *?\((.*) ?\;?/i";
|
$regex = "/(base64_decode|chr|php_uname|fwrite|fopen|fputs|passthru|popen|proc_open|shell_exec|exec|proc_nice|proc_terminate|proc_get_status|proc_close|pfsockopen|apache_child_terminate|posix_kill|posix_mkfifo|posix_setpgid|posix_setsid|posix_setuid|phpinfo) *?\((.*) ?\;?/i";
|
||||||
|
if(preg_match($regex,$input))
|
||||||
|
{
|
||||||
|
header('HTTP/1.0 400 Bad Request', true, 400);
|
||||||
|
exit();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check for XSS JS
|
||||||
|
$regex = "/(document\.location|document\.write|document\.cookie)/i";
|
||||||
if(preg_match($regex,$input))
|
if(preg_match($regex,$input))
|
||||||
{
|
{
|
||||||
header('HTTP/1.0 400 Bad Request', true, 400);
|
header('HTTP/1.0 400 Bad Request', true, 400);
|
||||||
|
Reference in New Issue
Block a user