noalyss-commit
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Noalyss-commit] [noalyss] 01/06: Security fix : f_id is a number


From: Dany De Bontridder
Subject: [Noalyss-commit] [noalyss] 01/06: Security fix : f_id is a number
Date: Sun, 3 Jun 2018 07:02:28 -0400 (EDT)

sparkyx pushed a commit to annotated tag rel7006
in repository noalyss.

commit 8d90926efe7bcdf17f0ab8363aa2e54a42f0198d
Author: Dany De Bontridder <address@hidden>
Date:   Sat Jun 2 08:28:44 2018 +0200

    Security fix : f_id is a number
---
 include/category_card.inc.php | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/category_card.inc.php b/include/category_card.inc.php
index 4e1b993..ce26bc1 100644
--- a/include/category_card.inc.php
+++ b/include/category_card.inc.php
@@ -34,7 +34,7 @@ global $http;
 
 $str_dossier=Dossier::get();
 
-$root="?".http_build_query(["ac"=>$http->request("ac"),"sb"=>"detail","f_id"=>$http->request("f_id")]);
+$root="?".http_build_query(["ac"=>$http->request("ac"),"sb"=>"detail","f_id"=>$http->request("f_id","number")]);
 $root.="&".$str_dossier;
 
 $ss_action=$http->request("sc", "string", "dc");



reply via email to

[Prev in Thread] Current Thread [Next in Thread]