[svn r15747] Patching own security patch

skala
Yannick Warnier 18 years ago
parent e263dbd167
commit d7f907cc0c
  1. 2
      user_portal.php

@ -767,7 +767,7 @@ $announcement = isset($_GET['announcement']) ? $_GET['announcement'] : -1;
$visibility = api_is_allowed_to_create_course() ? VISIBLE_TEACHER : VISIBLE_STUDENT;
SystemAnnouncementManager :: display_announcements($visibility, $announcement);
if (!empty ($_GET['include']) && preg_match('/^[a-zA-Z0-9_-]*\.html$/'))
if (!empty ($_GET['include']) && preg_match('/^[a-zA-Z0-9_-]*\.html$/',$_GET['include']))
{
include ('./home/'.$_GET['include']);
$pageIncluded = true;

Loading…
Cancel
Save