diff --git a/Logout.php b/Logout.php index d91fa3246..18d23b249 100644 --- a/Logout.php +++ b/Logout.php @@ -9,4 +9,6 @@ // Cleanup session_unset(); session_destroy(); +setcookie('PHPSESSID',"",time()-3600,'/'); + ?> \ No newline at end of file diff --git a/doc/Change.log b/doc/Change.log index fcbb51e26..4b5c0473b 100644 --- a/doc/Change.log +++ b/doc/Change.log @@ -1,5 +1,5 @@ webERP Change Log - +17/02/18 Exson: Fixed the DB_escape_string bug for Array in session.inc and destroy cookie while users log out in Logout.php 16/2/18 Paul Becker (PaulT commit): header.php: Add link to the Dashboard in the AppInfoUserDiv. (Forum contribution: http://www.weberp.org/forum/showthread.php?tid=8100) 16/2/18 PaulT: Remove unused $db parameter from many functions within the /api area. 16/2/18 PaulT: upgrade4.14.1-4.14.2.sql: Add SQL update to support commit 7961. diff --git a/includes/session.php b/includes/session.php index aaccea4ac..ea6d388d5 100644 --- a/includes/session.php +++ b/includes/session.php @@ -63,7 +63,8 @@ if(get_magic_quotes_gpc()) { $PostVariableValue[$PostArrayKey] = stripslashes($value[$PostArrayKey]); } - $PostVariableValue[$PostArrayKey] = DB_escape_string(htmlspecialchars($PostArrayValue,ENT_QUOTES,'UTF-8')); + $_POST[$PostVariableName][$PostArrayKey] = DB_escape_string(htmlspecialchars($PostArrayValue,ENT_QUOTES,'UTF-8')); + } } }