mirror of
https://github.com/manuelkasper/AS-Stats.git
synced 2025-02-20 11:44:12 +08:00
Fix security issue
'v' parameter of gengraph.php allowed shell command injection. Reported by Stefan Hanrath.
This commit is contained in:
parent
d7b806349c
commit
afe5f582d1
@ -30,7 +30,7 @@ $cmd = "$rrdtool graph - " .
|
||||
"--slope-mode --alt-autoscale -u 0 -l 0 --imgformat=PNG --base=1000 --height=$height --width=$width " .
|
||||
"--color BACK#ffffff00 --color SHADEA#ffffff00 --color SHADEB#ffffff00 ";
|
||||
|
||||
if (@$_GET['v'])
|
||||
if (isset($_GET['v']) && is_numeric($_GET['v']))
|
||||
$cmd .= "--title IPv" . $_GET['v'] . " ";
|
||||
|
||||
if (isset($_GET['nolegend']))
|
||||
|
Loading…
x
Reference in New Issue
Block a user