We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22827
    • 129 Posts
    Hello,

    I have noticed that in the sanity checking in the Request extender, there is this line:

    	if ((substr($name, 0, 6) == "ditto_" && $dID) && !in_array($saneName,$bad) && ($good == false || in_array($saneName,$good)) && !ereg("[\^`~!/@\\#\}\$%:;\)\(\{&\*=\'\+]", $value)){


    The line rejects any parameter containing "bad" characters. However, this includes the | symbol, which is the global delimiter.

    So if you have a multiple clause filter, it doesn’t work (name,frank,2|name,john,2).

    I think that the global delimiter should be removed from the illegal character list:

    $illegalChars = "[\^`~!/@\\#\}\$%:;\)\(\{&\*=\'\+]";
    $illegalChars = str_replace($globalDelimiter,"",$illegalChars);
    


    (this would require the global delimeter to be passed through, but this should be done anyway, as later the pipe symbol is hardcoded).

    Cheers,

    Paul