From b60a8c54f3abaaec88edd2e300acbf7cc43706af Mon Sep 17 00:00:00 2001 From: skodak Date: Tue, 11 Jul 2006 13:24:17 +0000 Subject: [PATCH] better cleaning of $file parameter SC#276; backported from MOODLE_16_STABLE --- help.php | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/help.php b/help.php index e4e950f53d0..23eef8f572c 100644 --- a/help.php +++ b/help.php @@ -16,16 +16,12 @@ require_once('config.php'); - $file = optional_param('file', '', PARAM_CLEAN); + $file = optional_param('file', '', PARAM_PATH); $text = optional_param('text', 'No text to display', PARAM_CLEAN); $module = optional_param('module', 'moodle', PARAM_ALPHAEXT); print_header(); - if (detect_munged_arguments($module .'/'. $file)) { - error('Filenames contain illegal characters!'); - } - print_simple_box_start('center', '96%'); $helpfound = false;