C:\Program Files (x86)\Apache Software Foundation\Apache2.2\htdocs\mamFM\globals.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
<?php
/**
 * @version $Id: globals.php 1145 2005-11-20 22:57:55Z Jinx $
 * @package Joomla
 * @copyright Copyright (C) 2005 Open Source Matters. All rights reserved.
 * @license http://www.gnu.org/copyleft/gpl.html GNU/GPL, see LICENSE.php
 * Joomla! is free software and parts of it may contain or be derived from the
 * GNU General Public License or other free or open source software licenses.
 * See COPYRIGHT.php for copyright notices and details.
 */

/**
 * Use 1 to emulate register_globals = on
 * 
 * Use 0 to emulate regsiter_globals = off
 */
define'RG_EMULATION');

/**
 * Adds an array to the GLOBALS array and checks that the GLOBALS variable is
 * not being attacked
 * @param array
 * @param boolean True if the array is to be added to the GLOBALS
 */
function checkInputArray( &$array$globalise=false ) {
    static 
$banned = array( '_files''_env''_get''_post''_cookie''_server''_session''globals' );

    foreach (
$array as $key => $value) {
        if (
in_arraystrtolower$key ), $banned ) ) {
            die( 
'Illegal variable <b>' implode'</b> or <b>'$banned ) . '</b> passed to script.' );
        }
        if (
$globalise) {
            
$GLOBALS[$key] = $value;
        }
    }
}

/**
 * Emulates register globals = off
 */
function unregisterGlobals () {
    
checkInputArray$_FILES );
    
checkInputArray$_ENV );
    
checkInputArray$_GET );
    
checkInputArray$_POST );
    
checkInputArray$_COOKIE );
    
checkInputArray$_SERVER );

    if (isset( 
$_SESSION )) {
        
checkInputArray$_SESSION );
    }

    
$REQUEST $_REQUEST;
    
$GET $_GET;
    
$POST $_POST;
    
$COOKIE $_COOKIE;
    if (isset ( 
$_SESSION )) {
        
$SESSION $_SESSION;
    }
    
$FILES $_FILES;
    
$ENV $_ENV;
    
$SERVER $_SERVER;
    foreach (
$GLOBALS as $key => $value) {
        if ( 
$key != 'GLOBALS' ) {
            unset ( 
$GLOBALS $key ] );
        }
    }
    
$_REQUEST $REQUEST;
    
$_GET $GET;
    
$_POST $POST;
    
$_COOKIE $COOKIE;
    if (isset ( 
$SESSION )) {
        
$_SESSION $SESSION;
    }
    
$_FILES $FILES;
    
$_ENV $ENV;
    
$_SERVER $SERVER;
}

/**
 * Emulates register globals = on
 */
function registerGlobals() {
    
checkInputArray$_FILEStrue );
    
checkInputArray$_ENVtrue );
    
checkInputArray$_GETtrue );
    
checkInputArray$_POSTtrue );
    
checkInputArray$_COOKIEtrue );
    
checkInputArray$_SERVERtrue );

    if (isset( 
$_SESSION )) {
        
checkInputArray$_SESSIONtrue );
    }

    foreach (
$_FILES as $key => $value){
        
$GLOBALS[$key] = $_FILES[$key]['tmp_name'];
        foreach (
$value as $ext => $value2){
            
$key2 $key '_' $ext;
            
$GLOBALS[$key2] = $value2;
        }
    }
}

if (
RG_EMULATION == 0) {
    
// force register_globals = off
    
unregisterGlobals();    
} else if (
ini_get('register_globals') == 0) {
    
// php.ini has register_globals = off and emulate = on
    
registerGlobals();
} else {
    
// php.ini has register_globals = on and emulate = on
    // just check for spoofing
    
checkInputArray$_FILES );
    
checkInputArray$_ENV );
    
checkInputArray$_GET );
    
checkInputArray$_POST );
    
checkInputArray$_COOKIE );
    
checkInputArray$_SERVER );

    if (isset( 
$_SESSION )) {
        
checkInputArray$_SESSION );
    }
}
?>