Forum Moderators: coopster
<?php
$path = 'includes/';
$default_page = 'home';
$page = isset( $_GET['page'] ) ? $_GET['page'] : $default_page;
$notallowed = array( '.', '\\', '/' );
if( file_exists( $path . $page . '.php' ) and !in_array( substr( $page, 1, 1 ), $notallowed ) and strpos( $page, '../' ) === false and strpos( $page, '..\\' ) === false )
{
include( $path . $page . '.php' );
}
else
{
include( $path . $default_page . '.php' );
}
?>
[edited by: eelixduppy at 2:47 pm (utc) on Apr 12, 2010]
[edit reason] no personal URLs, please [/edit]