From d2a0253d6eea6cfa8b7b91c5a43f310770c7902c Mon Sep 17 00:00:00 2001 From: Sven Slootweg Date: Fri, 11 May 2012 03:04:20 +0200 Subject: [PATCH] Add include verification --- frontend/module.admin.containers.php | 2 ++ frontend/module.admin.user.php | 2 ++ frontend/module.admin.users.php | 2 ++ frontend/module.vps.console.php | 2 ++ 4 files changed, 8 insertions(+) diff --git a/frontend/module.admin.containers.php b/frontend/module.admin.containers.php index dc73397..cb3de09 100644 --- a/frontend/module.admin.containers.php +++ b/frontend/module.admin.containers.php @@ -11,6 +11,8 @@ * licensing text. */ +if(!isset($_CVM)) { die("Unauthorized."); } + $sContainerList = array(); if($result = mysql_query_cached("SELECT * FROM containers")) diff --git a/frontend/module.admin.user.php b/frontend/module.admin.user.php index 304b4a1..7890e61 100644 --- a/frontend/module.admin.user.php +++ b/frontend/module.admin.user.php @@ -11,6 +11,8 @@ * licensing text. */ +if(!isset($_CVM)) { die("Unauthorized."); } + try { $sUserEntry = new User($router->uParameters[1]); diff --git a/frontend/module.admin.users.php b/frontend/module.admin.users.php index 18344d1..5e37246 100644 --- a/frontend/module.admin.users.php +++ b/frontend/module.admin.users.php @@ -11,6 +11,8 @@ * licensing text. */ +if(!isset($_CVM)) { die("Unauthorized."); } + $result = mysql_query_cached("SELECT * FROM users ORDER BY `AccessLevel` DESC"); $sUserList = array(); diff --git a/frontend/module.vps.console.php b/frontend/module.vps.console.php index f5cb3dc..731e36d 100644 --- a/frontend/module.vps.console.php +++ b/frontend/module.vps.console.php @@ -11,6 +11,8 @@ * licensing text. */ +if(!isset($_CVM)) { die("Unauthorized."); } + $sPageContents .= Templater::InlineRender("vps.console", $locale->strings, array( 'host' => htmlspecialchars($_SERVER['SERVER_NAME']) ));