Subversion Repositories eFlore/Applications.coel

Rev

Rev 1691 | Rev 1709 | Go to most recent revision | Show entire file | Ignore whitespace | Details | Blame | Last modification | View Log | RSS feed

Rev 1691 Rev 1697
Line 42... Line 42...
42
		// Connection à la base de données
42
		// Connection à la base de données
43
		$this->bdd = $this->connecterPDO($this->config, 'coel');
43
		$this->bdd = $this->connecterPDO($this->config, 'coel');
Line 44... Line 44...
44
		
44
		
45
		$this->gererSession($demarrer_session);
45
		$this->gererSession($demarrer_session);
-
 
46
		$this->gererIdentificationPermanente();
-
 
47
 
-
 
48
        if(isset($_GET['start'])) $this->start = intval($_GET['start']);
Line 46... Line 49...
46
		$this->gererIdentificationPermanente();
49
        if(isset($_GET['limit'])) $this->limit = intval($_GET['limit']);
47
		
50
		
48
		// Nettoyage du $_GET (sécurité)
51
		// Nettoyage du $_GET (non-sécurisé)
49
		if (isset($_GET)) {
52
		if (isset($_GET)) {
50
			$get_params = array('orderby', 'distinct', 'start', 'limit', 'formatRetour', 'searchCity');
53
			$get_params = array('orderby', 'distinct', 'formatRetour', 'searchCity');
51
			foreach ($get_params as $get) {
54
			foreach ($get_params as $get) {
52
				$verifier = array('NULL', "\n", "\r", "\\", "'", '"', "\x00", "\x1a", ';');
55
				$verifier = array('NULL', "\n", "\r", "\\", "'", '"', "\x00", "\x1a", ';');
53
				if (isset($_GET[$get]) && $_GET[$get] != '') {
56
				if (isset($_GET[$get]) && $_GET[$get] != '') {