Muhammad Jazman
Results
2
issues of
Muhammad Jazman
``` RewriteEngine On RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d # db, z x y .png RewriteRule tile/(.*)/(.*)/(.*)/(.*)\.jpg$ "mbtiles.php?db=$1&z=$2&x=$3&y=$4" [L] RewriteRule tile/(.*)/(.*)/(.*)/(.*)\.png$ "mbtiles.php?db=$1&z=$2&x=$3&y=$4" [L] ```
I think there is a needs to escape some bad ```$_GET``` variables ``` $zoom = intval($_GET['z']); $column = intval($_GET['x']); $row = intval($_GET['y']); $db = preg_replace("/[^a-z0-9_]/i","",$_GET['db']); $conn = new PDO("sqlite:". $db...