Attempt to deal with security issues which are arising in MODs which are not correctly setting phpbb_root_path and/or testing IN_PHPBB in their code

No functional changes to the behaviour of phpBB itself


git-svn-id: file:///svn/phpbb/branches/phpBB-2_0_0@5963 89ea8834-ac86-4346-8a33-228a782c2dd0
This commit is contained in:
Graham Eames 2006-05-23 21:11:56 +00:00
parent 0821474a5c
commit 44d3ba4582

View file

@ -24,8 +24,8 @@ if ( !defined('IN_PHPBB') )
die("Hacking attempt");
}
//
error_reporting (E_ERROR | E_WARNING | E_PARSE); // This will NOT report uninitialized variables
set_magic_quotes_runtime(0); // Disable magic_quotes_runtime
// The following code (unsetting globals)
@ -82,10 +82,11 @@ if (@ini_get('register_globals') == '1' || strtolower(@ini_get('register_globals
while (list($var,) = @each($input))
{
if (!in_array($var, $not_unset))
if (in_array($var, $not_unset))
{
unset($$var);
die('Hacking attempt!');
}
unset($$var);
}
unset($input);