From 9d66a521a14fcc331229596d511bd8963a0e92f4 Mon Sep 17 00:00:00 2001 From: Dhananjay Nakrani Date: Sun, 9 Feb 2014 13:26:33 +0530 Subject: [PATCH] Contest-5 Bug#4276. Signed-off-by: Dhananjay Nakrani --- index.php | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/index.php b/index.php index 61328fd68c..83c346cfbe 100644 --- a/index.php +++ b/index.php @@ -33,10 +33,20 @@ foreach ($drops as $each_drop) { } unset($drops, $each_drop); +/* + * Black list of all scripts to which front-end must submit data. + * Such scripts must not be loaded on home page. + * + */ + $target_blacklist = array ( + 'import.php', 'export.php' + ); + // If we have a valid target, let's load that script instead if (! empty($_REQUEST['target']) && is_string($_REQUEST['target']) && ! preg_match('/^index/', $_REQUEST['target']) + && ! in_array($_REQUEST['target'], $target_blacklist ) // Check if target is not in blacklist. && in_array($_REQUEST['target'], $goto_whitelist) ) { include $_REQUEST['target'];