Permalink
Browse files

$_FILES should also have slashes stripped if magic quotes are enabled.

  • Loading branch information...
reines committed May 26, 2011
1 parent 147e39b commit 3dda9ac89ada3d467b65e6ad06a48b74d56a1e40
Showing with 2 additions and 1 deletion.
  1. +2 −1 include/common.php
View
@@ -70,7 +70,7 @@
if (get_magic_quotes_runtime())
set_magic_quotes_runtime(0);
// Strip slashes from GET/POST/COOKIE (if magic_quotes_gpc is enabled)
// Strip slashes from GET/POST/COOKIE/REQUEST/FILES (if magic_quotes_gpc is enabled)
if (get_magic_quotes_gpc())
{
function stripslashes_array($array)
@@ -82,6 +82,7 @@ function stripslashes_array($array)
$_POST = stripslashes_array($_POST);
$_COOKIE = stripslashes_array($_COOKIE);
$_REQUEST = stripslashes_array($_REQUEST);
$_FILES = stripslashes_array($_FILES);
}
// If a cookie name is not specified in config.php, we use the default (pun_cookie)

0 comments on commit 3dda9ac

Please sign in to comment.