Fix command bash injection using filename + add constant to disable commands

This commit is contained in:
osaajani 2020-06-17 19:08:11 +02:00
parent 3839742f58
commit 39caa92a62
3 changed files with 25 additions and 4 deletions

View file

@ -27,6 +27,14 @@ namespace controllers\publics;
$this->internal_event = new \controllers\internals\Event($bdd);
\controllers\internals\Tool::verifyconnect();
if (!ENABLE_COMMAND)
{
\FlashMessage\FlashMessage::push('danger', 'Les commandes sont désactivées.');
$this->redirect(\descartes\Router::url('Dashboard', 'show'));
exit(0);
}
}
/**