瀏覽代碼

Add additional security improvements to the dev branch.

Mark Crane 13 年之前
父節點
當前提交
1efa2c765f
共有 1 個文件被更改,包括 4 次插入4 次删除
  1. 4 4
      v_exec.php

+ 4 - 4
v_exec.php

@@ -36,9 +36,9 @@ else {
 
 //get the html values and set them as variables
 	if (count($_POST)>0) {
-		$shell_cmd = trim($_POST["shell_cmd"]);
-		$php_cmd = trim($_POST["php_cmd"]);
-		$switch_cmd = trim($_POST["switch_cmd"]);
+		$shell_cmd = trim(check_str($_POST["shell_cmd"]));
+		$php_cmd = trim(check_str($_POST["php_cmd"]));
+		$switch_cmd = trim(check_str($_POST["switch_cmd"]));
 	}
 
 //show the header
@@ -201,4 +201,4 @@ else {
 
 //show the footer
 	require_once "includes/footer.php";
-?>
+?>