Use SCRIPT_NAME instead of PHP_SELF which won't send the PATH_INFO, this prevents XSS in old browsers. Thanks to Nico Golde.
parent
4d3c45a826
commit
4e5291c77a
Loading…
Reference in new issue