if (isset($_GET['xls']))
{
$filename = $_GET['filename'];
- $unique_name = $_GET['unique'];
+ $unique_name = preg_replace('/[^0-9a-z.]/i', '', $_GET['unique']);
$path = company_path(). '/pdf_files/';
header("Content-type: application/vnd.ms-excel");
header("Content-Disposition: attachment; filename=$filename" );
elseif (isset($_GET['xml']))
{
$filename = $_GET['filename'];
- $unique_name = $_GET['unique'];
+ $unique_name = preg_replace('/[^0-9a-z.]/i', '', $_GET['unique']);
$path = company_path(). '/pdf_files/';
header("content-type: text/xml");
header("Content-Disposition: attachment; filename=$filename");
? $_GET['PARAM_'.$i] : $def_pars[$i];
}
}
-$rep = $_POST['REP_ID'];
+
+$rep = preg_replace('/[^a-z_0-9]/i', '', $_POST['REP_ID']);
$rep_file = find_custom_file("/reporting/rep$rep.php");