security fixes to non-global users

git-svn-id: http://www.observium.org/svn/observer/trunk@455 61d68cd4-352d-0410-923a-c4978735b2b8
This commit is contained in:
Adam Amstrong
2009-08-12 15:20:20 +00:00
parent 9a16c803e6
commit a0153126f1
6 changed files with 20 additions and 6 deletions

View File

@@ -30,7 +30,7 @@ function createInterfaces(index)
echo("<div style='margin: 10px;'>");
if($_SESSION['userlevel'] != '10') { echo("<div class=error>You do not have then necessary permission to view this page!</div>"); } else {
if($_SESSION['userlevel'] != '10') { include("includes/error-no-perm.inc.php"); } else {
if($_GET['user_id']) {
$user_data = mysql_fetch_array(mysql_query("SELECT * FROM users WHERE user_id = '" . $_GET['user_id'] . "'"));