mirror of
				https://github.com/librenms/librenms.git
				synced 2024-10-07 16:52:45 +00:00 
			
		
		
		
	Security fix: unauthorized access (#10091)
* Security fix: unauthorized access Affects nginx users: Moved php files outside of public html directory (Apache was protected by .htaccess) Affects all users: Some files did not check for authentication and could disclose some info. Better checks before including files from user input * git mv html/includes/ includes/html git mv html/pages/ includes/html/
This commit is contained in:
		
							
								
								
									
										30
									
								
								includes/html/graphs/application/squid_objcount.inc.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										30
									
								
								includes/html/graphs/application/squid_objcount.inc.php
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,30 @@
 | 
			
		||||
<?php
 | 
			
		||||
 | 
			
		||||
$name = 'squid';
 | 
			
		||||
$app_id = $app['app_id'];
 | 
			
		||||
$colours       = 'mixed';
 | 
			
		||||
$unit_text     = 'objects';
 | 
			
		||||
$unitlen       = 10;
 | 
			
		||||
$bigdescrlen   = 15;
 | 
			
		||||
$smalldescrlen = 15;
 | 
			
		||||
$dostack       = 0;
 | 
			
		||||
$printtotal    = 0;
 | 
			
		||||
$addarea       = 1;
 | 
			
		||||
$transparency  = 15;
 | 
			
		||||
 | 
			
		||||
$rrd_filename = rrd_name($device['hostname'], array('app', $name, $app_id));
 | 
			
		||||
 | 
			
		||||
if (rrdtool_check_rrd_exists($rrd_filename)) {
 | 
			
		||||
    $rrd_list = array(
 | 
			
		||||
        array(
 | 
			
		||||
            'filename' => $rrd_filename,
 | 
			
		||||
            'descr'    => 'stored',
 | 
			
		||||
            'ds'       => 'numobjcount',
 | 
			
		||||
            'colour'   => '582a72'
 | 
			
		||||
        )
 | 
			
		||||
    );
 | 
			
		||||
} else {
 | 
			
		||||
    echo "file missing: $rrd_filename";
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
require 'includes/html/graphs/generic_v3_multiline.inc.php';
 | 
			
		||||
		Reference in New Issue
	
	Block a user