diff options
Diffstat (limited to 'Neutron-trunk/api/admin/appearance.php')
-rw-r--r--[-rwxr-xr-x] | Neutron-trunk/api/admin/appearance.php | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/Neutron-trunk/api/admin/appearance.php b/Neutron-trunk/api/admin/appearance.php index 28ebe74..ec0eece 100755..100644 --- a/Neutron-trunk/api/admin/appearance.php +++ b/Neutron-trunk/api/admin/appearance.php @@ -2,8 +2,9 @@ <?php require_once $_SERVER['DOCUMENT_ROOT'] . "/api/lang/processor.php"; +$num_samples = 2; -if (isset($_COOKIE['_NEUTRON_ADMIN_TOKEN']) && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != "." && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != ".." && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != "/") { +if (isset($_COOKIE['_NEUTRON_ADMIN_TOKEN']) && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != "." && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != ".." && $_COOKIE['_NEUTRON_ADMIN_TOKEN'] != "/" && strpos($_COOKIE['_NEUTRON_ADMIN_TOKEN'], "/") === false) { if (file_exists($_SERVER['DOCUMENT_ROOT'] . "/data/tokens/" . $_COOKIE['_NEUTRON_ADMIN_TOKEN'])) { if (isset($_POST['sitename'])) { if (trim($_POST['sitename']) == "") { |