From 9a0c9f42a142c2ff426e34f4cd7c972faef71fb2 Mon Sep 17 00:00:00 2001 From: "Fedor A. Fetisov" Date: Thu, 7 Nov 2013 02:55:14 +0400 Subject: [PATCH] Improve validation of incoming params --- src/mibew/libs/common.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/mibew/libs/common.php b/src/mibew/libs/common.php index 0a49253b..aad3687c 100644 --- a/src/mibew/libs/common.php +++ b/src/mibew/libs/common.php @@ -68,12 +68,12 @@ function myiconv($in_enc, $out_enc, $string) function verifyparam($name, $regexp, $default = null) { - if (isset($_GET[$name])) { + if (isset($_GET[$name]) && is_scalar($_GET[$name])) { $val = $_GET[$name]; if (preg_match($regexp, $val)) return $val; - } else if (isset($_POST[$name])) { + } else if (isset($_POST[$name]) && is_scalar($_POST[$name])) { $val = $_POST[$name]; if (preg_match($regexp, $val)) return $val;