better cleaning of $file parameter SC#276; merged from MOODLE_16_STABLE

This commit is contained in:
skodak 2006-07-11 13:19:52 +00:00
parent b2ec10959a
commit 496d06443a

View File

@ -16,17 +16,13 @@
require_once('config.php');
$file = optional_param('file', '', PARAM_CLEAN);
$file = optional_param('file', '', PARAM_PATH);
$text = optional_param('text', 'No text to display', PARAM_CLEAN);
$module = optional_param('module', 'moodle', PARAM_ALPHAEXT);
$forcelang = optional_param('forcelang', '', PARAM_ALPHAEXT);
print_header();
if (detect_munged_arguments($module .'/'. $file)) {
error('Filenames contain illegal characters!');
}
print_simple_box_start('center', '96%');
$helpfound = false;