aboutsummaryrefslogtreecommitdiffstats
path: root/phpBB
diff options
context:
space:
mode:
authorPaul S. Owen <psotfx@users.sourceforge.net>2001-04-29 21:20:19 +0000
committerPaul S. Owen <psotfx@users.sourceforge.net>2001-04-29 21:20:19 +0000
commit9c16714d85dbe7d5dd744ff38894436b04c1761c (patch)
tree9e04eb51e5bec14bc33c5687b14d604e746b2a90 /phpBB
parent085a3b07e9f3144e0c060c14ebcbec1dd7b45a5c (diff)
downloadforums-9c16714d85dbe7d5dd744ff38894436b04c1761c.tar
forums-9c16714d85dbe7d5dd744ff38894436b04c1761c.tar.gz
forums-9c16714d85dbe7d5dd744ff38894436b04c1761c.tar.bz2
forums-9c16714d85dbe7d5dd744ff38894436b04c1761c.tar.xz
forums-9c16714d85dbe7d5dd744ff38894436b04c1761c.zip
Added stripslashes to unserialize ... not a good idea to change php.ini updating code
git-svn-id: file:///svn/phpbb/trunk@218 89ea8834-ac86-4346-8a33-228a782c2dd0
Diffstat (limited to 'phpBB')
-rw-r--r--phpBB/includes/sessions.php6
1 files changed, 3 insertions, 3 deletions
diff --git a/phpBB/includes/sessions.php b/phpBB/includes/sessions.php
index 92cc7459e1..ca7a97ba2b 100644
--- a/phpBB/includes/sessions.php
+++ b/phpBB/includes/sessions.php
@@ -34,7 +34,7 @@ function session_begin($user_id, $user_ip, $page_id, $session_length, $login = F
global $cookiename, $cookiedomain, $cookiepath, $cookiesecure, $cookielife;
global $HTTP_COOKIE_VARS;
- $cookiedata = unserialize($HTTP_COOKIE_VARS[$cookiename]);
+ $cookiedata = unserialize(stripslashes($HTTP_COOKIE_VARS[$cookiename]));
$current_time = time();
$expiry_time = $current_time - $session_length;
$int_ip = encode_ip($user_ip);
@@ -148,7 +148,7 @@ function session_pagestart($user_ip, $thispage_id, $session_length)
global $cookiename, $cookiedomain, $cookiepath, $cookiesecure, $cookielife;
global $HTTP_COOKIE_VARS;
- $cookiedata = unserialize($HTTP_COOKIE_VARS[$cookiename]);
+ $cookiedata = unserialize(stripslashes($HTTP_COOKIE_VARS[$cookiename]));
$current_time = time();
$int_ip = encode_ip($user_ip);
unset($userdata);
@@ -336,7 +336,7 @@ function session_end($session_id, $user_id)
global $cookiename, $cookiedomain, $cookiepath, $cookiesecure, $cookielife;
global $HTTP_COOKIE_VARS;
- $cookiedata = unserialize($HTTP_COOKIE_VARS[$cookiename]);
+ $cookiedata = unserialize(stripslashes($HTTP_COOKIE_VARS[$cookiename]));
$current_time = time();
$sql = "UPDATE ".SESSIONS_TABLE."