mirror of
https://github.com/moodle/moodle.git
synced 2025-01-17 21:49:15 +01:00
better cleaning of $file parameter SC#276; merged from MOODLE_16_STABLE
This commit is contained in:
parent
b2ec10959a
commit
496d06443a
6
help.php
6
help.php
@ -16,17 +16,13 @@
|
||||
|
||||
require_once('config.php');
|
||||
|
||||
$file = optional_param('file', '', PARAM_CLEAN);
|
||||
$file = optional_param('file', '', PARAM_PATH);
|
||||
$text = optional_param('text', 'No text to display', PARAM_CLEAN);
|
||||
$module = optional_param('module', 'moodle', PARAM_ALPHAEXT);
|
||||
$forcelang = optional_param('forcelang', '', PARAM_ALPHAEXT);
|
||||
|
||||
print_header();
|
||||
|
||||
if (detect_munged_arguments($module .'/'. $file)) {
|
||||
error('Filenames contain illegal characters!');
|
||||
}
|
||||
|
||||
print_simple_box_start('center', '96%');
|
||||
|
||||
$helpfound = false;
|
||||
|
Loading…
x
Reference in New Issue
Block a user