Changeset 662428
- Timestamp:
- 02/02/2013 09:00:47 AM (13 years ago)
- Location:
- pafacile
- Files:
-
- 46 edited
- 42 copied
-
tags/2.5.10 (copied) (copied from pafacile/trunk)
-
tags/2.5.10/PAFacileBackend.php (copied) (copied from pafacile/trunk/PAFacileBackend.php)
-
tags/2.5.10/PAFacileFrontend.php (copied) (copied from pafacile/trunk/PAFacileFrontend.php)
-
tags/2.5.10/PAFacileUpdateManager.php (copied) (copied from pafacile/trunk/PAFacileUpdateManager.php)
-
tags/2.5.10/admin-pafacile.css (copied) (copied from pafacile/trunk/admin-pafacile.css)
-
tags/2.5.10/ajax/actions.php (copied) (copied from pafacile/trunk/ajax/actions.php)
-
tags/2.5.10/alboPretorio/dettaglio.php (copied) (copied from pafacile/trunk/alboPretorio/dettaglio.php) (1 diff)
-
tags/2.5.10/alboPretorio/elenco.php (copied) (copied from pafacile/trunk/alboPretorio/elenco.php) (1 diff)
-
tags/2.5.10/alboPretorio/stampa.php (copied) (copied from pafacile/trunk/alboPretorio/stampa.php) (1 diff)
-
tags/2.5.10/bandi/dettaglio.php (copied) (copied from pafacile/trunk/bandi/dettaglio.php) (1 diff)
-
tags/2.5.10/bandi/elenco.php (copied) (copied from pafacile/trunk/bandi/elenco.php) (1 diff)
-
tags/2.5.10/db.php (copied) (copied from pafacile/trunk/db.php)
-
tags/2.5.10/definitions.php (copied) (copied from pafacile/trunk/definitions.php)
-
tags/2.5.10/delibere/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/delibere/elenco.php (copied) (copied from pafacile/trunk/delibere/elenco.php) (1 diff)
-
tags/2.5.10/determine/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/determine/elenco.php (copied) (copied from pafacile/trunk/determine/elenco.php) (1 diff)
-
tags/2.5.10/doSave.php (copied) (copied from pafacile/trunk/doSave.php)
-
tags/2.5.10/google-analytics/index.php (copied) (copied from pafacile/trunk/google-analytics/index.php)
-
tags/2.5.10/images/tree/index.php (modified) (1 diff)
-
tags/2.5.10/incarichiProfessionali/dettaglio.php (copied) (copied from pafacile/trunk/incarichiProfessionali/dettaglio.php) (1 diff)
-
tags/2.5.10/incarichiProfessionali/elenco.php (copied) (copied from pafacile/trunk/incarichiProfessionali/elenco.php)
-
tags/2.5.10/mce/editor_plugin.dev.js (copied) (copied from pafacile/trunk/mce/editor_plugin.dev.js)
-
tags/2.5.10/ordinanze/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/ordinanze/elenco.php (copied) (copied from pafacile/trunk/ordinanze/elenco.php) (1 diff)
-
tags/2.5.10/organi/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/organi/elenco.php (copied) (copied from pafacile/trunk/organi/elenco.php) (1 diff)
-
tags/2.5.10/organigramma/dettaglio.php (copied) (copied from pafacile/trunk/organigramma/dettaglio.php) (1 diff)
-
tags/2.5.10/organigramma/elenco.php (copied) (copied from pafacile/trunk/organigramma/elenco.php) (1 diff)
-
tags/2.5.10/public-contents/AlboPretorio.php (copied) (copied from pafacile/trunk/public-contents/AlboPretorio.php) (1 diff)
-
tags/2.5.10/public-contents/BandiGare.php (copied) (copied from pafacile/trunk/public-contents/BandiGare.php) (1 diff)
-
tags/2.5.10/public-contents/Delibere.php (copied) (copied from pafacile/trunk/public-contents/Delibere.php) (1 diff)
-
tags/2.5.10/public-contents/Determine.php (copied) (copied from pafacile/trunk/public-contents/Determine.php) (1 diff)
-
tags/2.5.10/public-contents/Incarichi.php (copied) (copied from pafacile/trunk/public-contents/Incarichi.php) (1 diff)
-
tags/2.5.10/public-contents/Ordinanze.php (copied) (copied from pafacile/trunk/public-contents/Ordinanze.php) (1 diff)
-
tags/2.5.10/public-contents/Organi.php (copied) (copied from pafacile/trunk/public-contents/Organi.php) (1 diff)
-
tags/2.5.10/public-contents/Sovvenzioni.php (copied) (copied from pafacile/trunk/public-contents/Sovvenzioni.php) (2 diffs)
-
tags/2.5.10/public-contents/iContents.php (copied) (copied from pafacile/trunk/public-contents/iContents.php)
-
tags/2.5.10/readme.txt (copied) (copied from pafacile/trunk/readme.txt) (3 diffs)
-
tags/2.5.10/scripts/jq.pafacile.js (copied) (copied from pafacile/trunk/scripts/jq.pafacile.js)
-
tags/2.5.10/sovvenzioni (copied) (copied from pafacile/trunk/sovvenzioni)
-
tags/2.5.10/sovvenzioni/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/sovvenzioni/elenco.php (modified) (1 diff)
-
tags/2.5.10/tipiAtto/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/tipiAtto/elenco.php (modified) (1 diff)
-
tags/2.5.10/tipiOrgani/dettaglio.php (modified) (1 diff)
-
tags/2.5.10/tipiOrgani/elenco.php (modified) (1 diff)
-
tags/2.5.10/toSendIt.php (copied) (copied from pafacile/trunk/toSendIt.php)
-
tags/2.5.10/toSendItPAFacileContents.php (copied) (copied from pafacile/trunk/toSendItPAFacileContents.php) (1 diff)
-
tags/2.5.10/toSendItPAFacilePages.php (copied) (copied from pafacile/trunk/toSendItPAFacilePages.php)
-
tags/2.5.10/toSendItPAFacileWidgets.php (copied) (copied from pafacile/trunk/toSendItPAFacileWidgets.php)
-
tags/2.5.10/tosendit-pa.php (copied) (copied from pafacile/trunk/tosendit-pa.php) (3 diffs)
-
tags/2.5.10/welcome.php (copied) (copied from pafacile/trunk/welcome.php) (1 diff)
-
trunk/alboPretorio/dettaglio.php (modified) (1 diff)
-
trunk/alboPretorio/elenco.php (modified) (1 diff)
-
trunk/alboPretorio/stampa.php (modified) (1 diff)
-
trunk/bandi/dettaglio.php (modified) (1 diff)
-
trunk/bandi/elenco.php (modified) (1 diff)
-
trunk/delibere/dettaglio.php (modified) (1 diff)
-
trunk/delibere/elenco.php (modified) (1 diff)
-
trunk/determine/dettaglio.php (modified) (1 diff)
-
trunk/determine/elenco.php (modified) (1 diff)
-
trunk/images/tree/index.php (modified) (1 diff)
-
trunk/incarichiProfessionali/dettaglio.php (modified) (1 diff)
-
trunk/ordinanze/dettaglio.php (modified) (1 diff)
-
trunk/ordinanze/elenco.php (modified) (1 diff)
-
trunk/organi/dettaglio.php (modified) (1 diff)
-
trunk/organi/elenco.php (modified) (1 diff)
-
trunk/organigramma/dettaglio.php (modified) (1 diff)
-
trunk/organigramma/elenco.php (modified) (1 diff)
-
trunk/public-contents/AlboPretorio.php (modified) (1 diff)
-
trunk/public-contents/BandiGare.php (modified) (1 diff)
-
trunk/public-contents/Delibere.php (modified) (1 diff)
-
trunk/public-contents/Determine.php (modified) (1 diff)
-
trunk/public-contents/Incarichi.php (modified) (1 diff)
-
trunk/public-contents/Ordinanze.php (modified) (1 diff)
-
trunk/public-contents/Organi.php (modified) (1 diff)
-
trunk/public-contents/Sovvenzioni.php (modified) (2 diffs)
-
trunk/readme.txt (modified) (3 diffs)
-
trunk/sovvenzioni/dettaglio.php (modified) (1 diff)
-
trunk/sovvenzioni/elenco.php (modified) (1 diff)
-
trunk/tipiAtto/dettaglio.php (modified) (1 diff)
-
trunk/tipiAtto/elenco.php (modified) (1 diff)
-
trunk/tipiOrgani/dettaglio.php (modified) (1 diff)
-
trunk/tipiOrgani/elenco.php (modified) (1 diff)
-
trunk/toSendItPAFacileContents.php (modified) (1 diff)
-
trunk/tosendit-pa.php (modified) (3 diffs)
-
trunk/welcome.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
pafacile/tags/2.5.10/alboPretorio/dettaglio.php
r654497 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 function buildModuloAlboPretorio(){ 3 14 global $wpdb, $current_user; -
pafacile/tags/2.5.10/alboPretorio/elenco.php
r649783 r662428 1 <?php 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function displayAlboPretorioPublic($params, $extraParams = array()){ 3 13 global $wpdb; -
pafacile/tags/2.5.10/alboPretorio/stampa.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function buildStampaAlboPretorio(){ 3 13 global $wpdb, $current_user; -
pafacile/tags/2.5.10/bandi/dettaglio.php
r648290 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function adminDettaglioBandi(){ 3 15 global $wpdb; -
pafacile/tags/2.5.10/bandi/elenco.php
r632155 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 3 13 function displayBandiPublic($params, $extraParams = array()){ -
pafacile/tags/2.5.10/delibere/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 global $wpdb; 3 14 $tableName = $wpdb->prefix . TOSENDIT_PAFACILE_DB_DELIBERE; -
pafacile/tags/2.5.10/delibere/elenco.php
r619814 r662428 1 1 <?php 2 #require_once 'public-contents/Delibere.php'; 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 3 11 4 12 function displayDeliberePublic($params, $extraParams = array()){ -
pafacile/tags/2.5.10/determine/dettaglio.php
r470551 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 global $wpdb, $current_user; 3 13 $tableName = $wpdb->prefix . TOSENDIT_PAFACILE_DB_DETERMINE; -
pafacile/tags/2.5.10/determine/elenco.php
r619814 r662428 1 1 <?php 2 2 # require_once 'public-contents/Determine.php'; 3 /* 4 * Sinve Version 2.5.10 5 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 6 */ 7 if (!empty($_SERVER['SCRIPT_FILENAME']) && 8 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 9 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 10 ) 11 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 3 12 4 13 function displayDeterminePublic($params, $extraParams = array()){ -
pafacile/tags/2.5.10/images/tree/index.php
r459538 r662428 5 5 $basedir = dirname(__FILE__) .'/'; 6 6 $structure = $_GET['structure']; 7 if( file_exists("$basedir$structure.gif")){7 if(is_numeric($_GET['structure']) && file_exists("$basedir$structure.gif")){ 8 8 header("Location: $structure.gif"); 9 9 exit(); 10 10 } 11 11 if(!is_numeric($_GET['structure'])){ 12 13 die("Codice struttura invalido"); 14 15 } 12 16 $l = strlen($structure); 13 17 if($l==0){ -
pafacile/tags/2.5.10/incarichiProfessionali/dettaglio.php
r559534 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function getDettaglio(){ 3 13 global $wpdb, $current_user; -
pafacile/tags/2.5.10/ordinanze/dettaglio.php
r470551 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 global $wpdb, $current_user; 3 13 -
pafacile/tags/2.5.10/ordinanze/elenco.php
r619814 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function displayOrdinanze(){ 3 15 toSendItGenericMethods::mergeSearchFilter('ricerca_ordinanze'); -
pafacile/tags/2.5.10/organi/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function organiDettaglio(){ 3 15 -
pafacile/tags/2.5.10/organi/elenco.php
r619814 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 function displayOrgani(){ 3 14 toSendItGenericMethods::mergeSearchFilter('ricerca_organi'); -
pafacile/tags/2.5.10/organigramma/dettaglio.php
r611965 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function displayDettaglioOrganigramma(){ 3 15 global $wpdb; -
pafacile/tags/2.5.10/organigramma/elenco.php
r611965 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 -
pafacile/tags/2.5.10/public-contents/AlboPretorio.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzazione pubblica dell'albo pretorio: -
pafacile/tags/2.5.10/public-contents/BandiGare.php
r648290 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/iContents.php'; 3 14 -
pafacile/tags/2.5.10/public-contents/Delibere.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzazione pubblica delle delibere: -
pafacile/tags/2.5.10/public-contents/Determine.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 3 13 /**************************************************************** -
pafacile/tags/2.5.10/public-contents/Incarichi.php
r559534 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzaizone degli incarichi professionali -
pafacile/tags/2.5.10/public-contents/Ordinanze.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzaizone delle ordinanze -
pafacile/tags/2.5.10/public-contents/Organi.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 /* ************************************************** -
pafacile/tags/2.5.10/public-contents/Sovvenzioni.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/iContents.php'; 3 13 class Sovvenzioni extends PAFacilePublicBaseClass implements iContents { … … 57 67 58 68 echo $buffer; 69 /* 70 * Since Ver. 2.5.10 71 * Assenza del box di upload 72 */ 73 toSendItGenericMethods::displayFileUploadBox($tableName, $itemId); 59 74 60 75 return true; -
pafacile/tags/2.5.10/readme.txt
r661392 r662428 5 5 Requires at least: 3.4 6 6 Tested up to: 3.5 7 Stable tag: 2.5. 97 Stable tag: 2.5.10 8 8 License: GPLv3 9 9 … … 12 12 == Description == 13 13 14 **NOTA:** Aggiornare immediatamente PAFacile se si sta utilizzando una versione precedente alla 2.5.9. 14 **NOTA:** Aggiornare immediatamente PAFacile se si sta utilizzando una versione precedente alla 2.5.10. 15 È stata scoperta una vulnerabilità di tipo XSS per la quale un individuo potrebbe iniettare del codice 16 Javascript in alcune delle pagine del sito veicolando eventuali codici malevoli verso gli utenti ignari. 15 17 16 18 PAFacile è un plugin sviluppato dalla [toSend.it](http://tosend.it) per venire incontro alle esigenze della Pubblica Amministrazione e degli Enti Locali creando uno strumento semplice da usare e facile da manutenere e intuitivo nella sua configurazione. … … 72 74 73 75 == Changelog == 76 77 = 2.5.10 (2013-02-02) = 78 * **Update:** Aggiunto box dei file alla sezione pubblica delle sovvenzioni. 79 * **Security:** Corretto il codice per evitare un attacco di tipo XSS (thanks to Dejan Lukan). 74 80 75 81 = 2.5.9 (2013-01-30) = -
pafacile/tags/2.5.10/sovvenzioni/dettaglio.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function buildModuloSovvenzioni(){ 3 13 global $wpdb, $current_user; -
pafacile/tags/2.5.10/sovvenzioni/elenco.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function displaySovvenzioniPublic($params, $extraParams = array()){ 3 13 global $wpdb; -
pafacile/tags/2.5.10/tipiAtto/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function adminDettaglioTipiAtto(){ 3 13 global $wpdb; -
pafacile/tags/2.5.10/tipiAtto/elenco.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 /* ===================== 3 13 * SINCE VERSION 1.5.6 -
pafacile/tags/2.5.10/tipiOrgani/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 class adminFormBuilder{ -
pafacile/tags/2.5.10/tipiOrgani/elenco.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 /* ===================== 3 13 * SINCE VERSION 1.5.6 -
pafacile/tags/2.5.10/toSendItPAFacileContents.php
r643338 r662428 1 1 <?php 2 3 /* 4 * Sinve Version 2.5.10 5 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 6 */ 7 if (!empty($_SERVER['SCRIPT_FILENAME']) && 8 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 9 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 10 ) 11 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 12 2 13 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/Determine.php'; 3 14 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/Delibere.php'; -
pafacile/tags/2.5.10/tosendit-pa.php
r661392 r662428 3 3 * @package toSend.it 4 4 * @author toSend.it di Luisa Marra 5 * @version 2.5. 95 * @version 2.5.10 6 6 */ 7 7 /* … … 10 10 Description: PAFacile è un plugin nato per consentire alle pubbliche amministrazione di gestire la trasparenza amministrativa secondo gli obblighi di legge. Il plugin è l'unico in Italia a consentire l'adeguamento di un sito web di una pubblica amministrazione agli ultimi aggiornamenti normativa in materia di Albo Pretorio on-line, Bandi di Gara, Delbere e determinazioni, Ordinanze, Organigramma, Incarichi professionali, Sovvenzioni. 11 11 Author: toSend.it di Luisa Marra 12 Version: 2.5. 912 Version: 2.5.10 13 13 Author URI: http://toSend.it 14 14 */ … … 30 30 #define('TOSENDIT_PAFACILE_VERSION', '2.5.7'); 31 31 #define('TOSENDIT_PAFACILE_VERSION', '2.5.8'); 32 define('TOSENDIT_PAFACILE_VERSION', '2.5.9'); 32 #define('TOSENDIT_PAFACILE_VERSION', '2.5.9'); 33 define('TOSENDIT_PAFACILE_VERSION', '2.5.10'); 33 34 34 35 # è PAFacile in un installazione di default -
pafacile/tags/2.5.10/welcome.php
r649783 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 function pageWelcomeVersionOutput($currentVersion, $minimalVersion ){ -
pafacile/trunk/alboPretorio/dettaglio.php
r654497 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 function buildModuloAlboPretorio(){ 3 14 global $wpdb, $current_user; -
pafacile/trunk/alboPretorio/elenco.php
r649783 r662428 1 <?php 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function displayAlboPretorioPublic($params, $extraParams = array()){ 3 13 global $wpdb; -
pafacile/trunk/alboPretorio/stampa.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function buildStampaAlboPretorio(){ 3 13 global $wpdb, $current_user; -
pafacile/trunk/bandi/dettaglio.php
r648290 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function adminDettaglioBandi(){ 3 15 global $wpdb; -
pafacile/trunk/bandi/elenco.php
r632155 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 3 13 function displayBandiPublic($params, $extraParams = array()){ -
pafacile/trunk/delibere/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 global $wpdb; 3 14 $tableName = $wpdb->prefix . TOSENDIT_PAFACILE_DB_DELIBERE; -
pafacile/trunk/delibere/elenco.php
r619814 r662428 1 1 <?php 2 #require_once 'public-contents/Delibere.php'; 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 3 11 4 12 function displayDeliberePublic($params, $extraParams = array()){ -
pafacile/trunk/determine/dettaglio.php
r470551 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 global $wpdb, $current_user; 3 13 $tableName = $wpdb->prefix . TOSENDIT_PAFACILE_DB_DETERMINE; -
pafacile/trunk/determine/elenco.php
r619814 r662428 1 1 <?php 2 2 # require_once 'public-contents/Determine.php'; 3 /* 4 * Sinve Version 2.5.10 5 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 6 */ 7 if (!empty($_SERVER['SCRIPT_FILENAME']) && 8 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 9 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 10 ) 11 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 3 12 4 13 function displayDeterminePublic($params, $extraParams = array()){ -
pafacile/trunk/images/tree/index.php
r459538 r662428 5 5 $basedir = dirname(__FILE__) .'/'; 6 6 $structure = $_GET['structure']; 7 if( file_exists("$basedir$structure.gif")){7 if(is_numeric($_GET['structure']) && file_exists("$basedir$structure.gif")){ 8 8 header("Location: $structure.gif"); 9 9 exit(); 10 10 } 11 11 if(!is_numeric($_GET['structure'])){ 12 13 die("Codice struttura invalido"); 14 15 } 12 16 $l = strlen($structure); 13 17 if($l==0){ -
pafacile/trunk/incarichiProfessionali/dettaglio.php
r559534 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function getDettaglio(){ 3 13 global $wpdb, $current_user; -
pafacile/trunk/ordinanze/dettaglio.php
r470551 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 global $wpdb, $current_user; 3 13 -
pafacile/trunk/ordinanze/elenco.php
r619814 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function displayOrdinanze(){ 3 15 toSendItGenericMethods::mergeSearchFilter('ricerca_ordinanze'); -
pafacile/trunk/organi/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function organiDettaglio(){ 3 15 -
pafacile/trunk/organi/elenco.php
r619814 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 function displayOrgani(){ 3 14 toSendItGenericMethods::mergeSearchFilter('ricerca_organi'); -
pafacile/trunk/organigramma/dettaglio.php
r611965 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 13 2 14 function displayDettaglioOrganigramma(){ 3 15 global $wpdb; -
pafacile/trunk/organigramma/elenco.php
r611965 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 -
pafacile/trunk/public-contents/AlboPretorio.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzazione pubblica dell'albo pretorio: -
pafacile/trunk/public-contents/BandiGare.php
r648290 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/iContents.php'; 3 14 -
pafacile/trunk/public-contents/Delibere.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzazione pubblica delle delibere: -
pafacile/trunk/public-contents/Determine.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 3 13 /**************************************************************** -
pafacile/trunk/public-contents/Incarichi.php
r559534 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzaizone degli incarichi professionali -
pafacile/trunk/public-contents/Ordinanze.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 12 2 13 /**************************************************************** 3 14 * Procedure per la visualizzaizone delle ordinanze -
pafacile/trunk/public-contents/Organi.php
r525549 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 /* ************************************************** -
pafacile/trunk/public-contents/Sovvenzioni.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/iContents.php'; 3 13 class Sovvenzioni extends PAFacilePublicBaseClass implements iContents { … … 57 67 58 68 echo $buffer; 69 /* 70 * Since Ver. 2.5.10 71 * Assenza del box di upload 72 */ 73 toSendItGenericMethods::displayFileUploadBox($tableName, $itemId); 59 74 60 75 return true; -
pafacile/trunk/readme.txt
r661392 r662428 5 5 Requires at least: 3.4 6 6 Tested up to: 3.5 7 Stable tag: 2.5. 97 Stable tag: 2.5.10 8 8 License: GPLv3 9 9 … … 12 12 == Description == 13 13 14 **NOTA:** Aggiornare immediatamente PAFacile se si sta utilizzando una versione precedente alla 2.5.9. 14 **NOTA:** Aggiornare immediatamente PAFacile se si sta utilizzando una versione precedente alla 2.5.10. 15 È stata scoperta una vulnerabilità di tipo XSS per la quale un individuo potrebbe iniettare del codice 16 Javascript in alcune delle pagine del sito veicolando eventuali codici malevoli verso gli utenti ignari. 15 17 16 18 PAFacile è un plugin sviluppato dalla [toSend.it](http://tosend.it) per venire incontro alle esigenze della Pubblica Amministrazione e degli Enti Locali creando uno strumento semplice da usare e facile da manutenere e intuitivo nella sua configurazione. … … 72 74 73 75 == Changelog == 76 77 = 2.5.10 (2013-02-02) = 78 * **Update:** Aggiunto box dei file alla sezione pubblica delle sovvenzioni. 79 * **Security:** Corretto il codice per evitare un attacco di tipo XSS (thanks to Dejan Lukan). 74 80 75 81 = 2.5.9 (2013-01-30) = -
pafacile/trunk/sovvenzioni/dettaglio.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function buildModuloSovvenzioni(){ 3 13 global $wpdb, $current_user; -
pafacile/trunk/sovvenzioni/elenco.php
r643338 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function displaySovvenzioniPublic($params, $extraParams = array()){ 3 13 global $wpdb; -
pafacile/trunk/tipiAtto/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 function adminDettaglioTipiAtto(){ 3 13 global $wpdb; -
pafacile/trunk/tipiAtto/elenco.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 /* ===================== 3 13 * SINCE VERSION 1.5.6 -
pafacile/trunk/tipiOrgani/dettaglio.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 class adminFormBuilder{ -
pafacile/trunk/tipiOrgani/elenco.php
r459538 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 11 2 12 /* ===================== 3 13 * SINCE VERSION 1.5.6 -
pafacile/trunk/toSendItPAFacileContents.php
r643338 r662428 1 1 <?php 2 3 /* 4 * Sinve Version 2.5.10 5 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 6 */ 7 if (!empty($_SERVER['SCRIPT_FILENAME']) && 8 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 9 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 10 ) 11 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 12 2 13 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/Determine.php'; 3 14 require_once PAFACILE_PLUING_DIRECTORY .'/public-contents/Delibere.php'; -
pafacile/trunk/tosendit-pa.php
r661392 r662428 3 3 * @package toSend.it 4 4 * @author toSend.it di Luisa Marra 5 * @version 2.5. 95 * @version 2.5.10 6 6 */ 7 7 /* … … 10 10 Description: PAFacile è un plugin nato per consentire alle pubbliche amministrazione di gestire la trasparenza amministrativa secondo gli obblighi di legge. Il plugin è l'unico in Italia a consentire l'adeguamento di un sito web di una pubblica amministrazione agli ultimi aggiornamenti normativa in materia di Albo Pretorio on-line, Bandi di Gara, Delbere e determinazioni, Ordinanze, Organigramma, Incarichi professionali, Sovvenzioni. 11 11 Author: toSend.it di Luisa Marra 12 Version: 2.5. 912 Version: 2.5.10 13 13 Author URI: http://toSend.it 14 14 */ … … 30 30 #define('TOSENDIT_PAFACILE_VERSION', '2.5.7'); 31 31 #define('TOSENDIT_PAFACILE_VERSION', '2.5.8'); 32 define('TOSENDIT_PAFACILE_VERSION', '2.5.9'); 32 #define('TOSENDIT_PAFACILE_VERSION', '2.5.9'); 33 define('TOSENDIT_PAFACILE_VERSION', '2.5.10'); 33 34 34 35 # è PAFacile in un installazione di default -
pafacile/trunk/welcome.php
r649783 r662428 1 1 <?php 2 /* 3 * Sinve Version 2.5.10 4 * Avoid XSS vulnerability discovered by Dejan Lukan many thanks! 5 */ 6 if (!empty($_SERVER['SCRIPT_FILENAME']) && 7 basename(__FILE__) == basename($_SERVER['SCRIPT_FILENAME']) && // Same script file 8 basename(dirname(__FILE__)) == basename(dirname($_SERVER['SCRIPT_FILENAME'])) // Same directory 9 ) 10 die ('Please do not load this page directly. Thanks to Dejan Lukan for the notification!'); 2 11 3 12 function pageWelcomeVersionOutput($currentVersion, $minimalVersion ){
Note: See TracChangeset
for help on using the changeset viewer.