mirror of
https://github.com/phpbb/phpbb.git
synced 2025-06-10 05:18:52 +00:00
[ticket/13765] Verify SERVER_PROTOCOL has the expected format before using it.
PHPBB3-13765
This commit is contained in:
parent
35d2467c94
commit
463c62df18
2 changed files with 2 additions and 2 deletions
|
@ -2782,7 +2782,7 @@ function send_status_line($code, $message)
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
if (!empty($_SERVER['SERVER_PROTOCOL']))
|
if (!empty($_SERVER['SERVER_PROTOCOL']) && is_string($_SERVER['SERVER_PROTOCOL']) && preg_match('#^HTTP/[0-9]\.[0-9]$#', $_SERVER['SERVER_PROTOCOL']))
|
||||||
{
|
{
|
||||||
$version = $_SERVER['SERVER_PROTOCOL'];
|
$version = $_SERVER['SERVER_PROTOCOL'];
|
||||||
}
|
}
|
||||||
|
|
|
@ -130,7 +130,7 @@ if (phpbb_has_trailing_path($phpEx))
|
||||||
{
|
{
|
||||||
$prefix = 'Status:';
|
$prefix = 'Status:';
|
||||||
}
|
}
|
||||||
else if (!empty($_SERVER['SERVER_PROTOCOL']))
|
else if (!empty($_SERVER['SERVER_PROTOCOL']) && is_string($_SERVER['SERVER_PROTOCOL']) && preg_match('#^HTTP/[0-9]\.[0-9]$#', $_SERVER['SERVER_PROTOCOL']))
|
||||||
{
|
{
|
||||||
$prefix = $_SERVER['SERVER_PROTOCOL'];
|
$prefix = $_SERVER['SERVER_PROTOCOL'];
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Reference in a new issue