diff --git a/config_defaults_inc.php b/config_defaults_inc.php index c4bcebbe51..f970903d30 100644 --- a/config_defaults_inc.php +++ b/config_defaults_inc.php @@ -126,10 +126,20 @@ $t_host = 'localhost'; } - $t_path = str_replace( basename( $_SERVER['PHP_SELF'] ), '', $_SERVER['PHP_SELF'] ); + if( isset( $_SERVER['SCRIPT_NAME'] ) ) { + $t_self = $_SERVER['SCRIPT_NAME']; + } else { + $t_self = $_SERVER['PHP_SELF']; + } + + $t_self = filter_var($t_self, FILTER_SANITIZE_STRING); + $t_path = str_replace( basename( $t_self ), '', $t_self ); $t_path = basename( $t_path ) == "admin" ? rtrim( dirname( $t_path ), '/\\' ) . '/' : $t_path; $t_path = basename( $t_path ) == "soap" ? rtrim( dirname( dirname( $t_path ) ), '/\\' ) . '/' : $t_path; - + if( strpos( $t_path, '&#' ) ) { + echo 'Can not safely determine $g_path. Please set $g_path manually in config_inc.php'; + die; + } $t_url = $t_protocol . '://' . $t_host . $t_path; } else {