Pārlūkot izejas kodu

Sanitize Login for Logger

own3mall 4 gadi atpakaļ
vecāks
revīzija
2ceb1b4ae0
1 mainītis faili ar 2 papildinājumiem un 2 dzēšanām
  1. 2 2
      index.php

+ 2 - 2
index.php

@@ -297,7 +297,7 @@ function ogpHome()
 					if( !$banlist_info )
 					if( !$banlist_info )
 						$db->query("INSERT INTO `OGP_DB_PREFIXban_list` (`client_ip`) VALUES('$client_ip');");
 						$db->query("INSERT INTO `OGP_DB_PREFIXban_list` (`client_ip`) VALUES('$client_ip');");
 						
 						
-					$db->logger( get_lang("bad_login") . " ( Banned until " . date("r", $banned_until) . " ) [ " . login . ": $_POST[ulogin], " . password . ": ******** ]" );
+					$db->logger( get_lang("bad_login") . " ( Banned until " . date("r", $banned_until) . " ) [ " . login . ": " . sanitizeInputStr($_POST["ulogin"]) . ", " . password . ": ******** ]" );
 					$db->query("UPDATE `OGP_DB_PREFIXban_list` SET logging_attempts='$login_attempts', banned_until='$banned_until' WHERE client_ip='$client_ip';");
 					$db->query("UPDATE `OGP_DB_PREFIXban_list` SET logging_attempts='$login_attempts', banned_until='$banned_until' WHERE client_ip='$client_ip';");
 					print_failure("Banned until " . date("r",$banned_until));
 					print_failure("Banned until " . date("r",$banned_until));
 				}
 				}
@@ -306,7 +306,7 @@ function ogpHome()
 					if( !$banlist_info )
 					if( !$banlist_info )
 						$db->query("INSERT INTO `OGP_DB_PREFIXban_list` (`client_ip`) VALUES('$client_ip');");
 						$db->query("INSERT INTO `OGP_DB_PREFIXban_list` (`client_ip`) VALUES('$client_ip');");
 					
 					
-					$db->logger( get_lang("bad_login") . " ( $login_attempts ) [ " . get_lang("login") . ": $_POST[ulogin], " . get_lang("password") . ": ******** ]" );
+					$db->logger( get_lang("bad_login") . " ( $login_attempts ) [ " . get_lang("login") . ": " . sanitizeInputStr($_POST["ulogin"]) . ", " . get_lang("password") . ": ******** ]" );
 					$db->query("UPDATE `OGP_DB_PREFIXban_list` SET logging_attempts='$login_attempts' WHERE client_ip='$client_ip';");
 					$db->query("UPDATE `OGP_DB_PREFIXban_list` SET logging_attempts='$login_attempts' WHERE client_ip='$client_ip';");
 					$view->refresh("index.php",2);
 					$view->refresh("index.php",2);
 				}
 				}