unset $_language in case of malicious entry via url w/ register_globals.
authorRobert Treat <xzilla@users.sourceforge.net>
Thu, 18 Dec 2008 04:59:17 +0000 (23:59 -0500)
committerRobert Treat <xzilla@users.sourceforge.net>
Thu, 18 Dec 2008 04:59:17 +0000 (23:59 -0500)
libraries/lib.inc.php

index d425dc15041036c1748823a8bf611026c7654665..fe2d9e6cae1449b17b6e696b2e77f290f64bfe7c 100644 (file)
@@ -95,6 +95,8 @@
        }
 
        // Determine language file to import:
+       unset($_language);
+
        // 1. Check for the language from a request var
        if (isset($_REQUEST['language']) && isset($appLangFiles[$_REQUEST['language']]))
                $_language = $_REQUEST['language'];