hyannis/index.php check
site being worked on, back soon
/*$showvars = "n"; # 'y' for 'yes', anything else for 'no' include ("ccpj.inc"); if ($showvars == "y") {echo "\$page: $page
";} // this line broken? ######## if register_globals is disabled, use this # get the (desired, but untrusted) vars # then allow var only if a simple filename (no path) $page = $_REQUEST['page']; if ($page == "" and $q == "") {$page = "01-Home";} # what if page=="n"? $q = $_REQUEST['q']; $n = $_REQUEST['n']; if (isset($page)) { if ($page !== basename($page)) { die("invalid input"); } } if (isset($q)) { $vetted = basename($q); if ($q !== $vetted) { die("invalid input"); } } if (isset($n)) { $vetted = basename($n); if ($n !== $vetted) { die("invalid input"); } } ######## end register_globals fix print << HTML; # create title based upon $page title($page, $q); // located in ccpj.inc; what if page=="n"? // print <<
 ccpj logo  Cape Codders for Peace and Justice
   a coalition of individuals and organizations
Subscribe to
Email Newsletter

HTML; navcol(); // located in ccpj.inc // if ($page == "01-Home") navcolextra(); print << -->
HTML; if ($q!= "") { if (file_exists("qpgs/$q.php")) include("qpgs/$q.php"); elseif (file_exists("qpgs/$q")) include("qpgs/$q"); else print "The file $q does not exist.
\n"; } elseif ($n!= "") { print('Back to CCPJ Media Coverage

'); if (file_exists("news/$n.php")) include("news/$n.php"); else print "The file $n does not exist.
\n"; print('

Back to CCPJ Media Coverage'); } else if (file_exists("pages/$page.php")) include("pages/$page.php"); else print "The file $page does not exist.
\n"; print <<
Fair Use Clause Original content © 2003, 2004, Cape Codders for Peace and Justice, all rights reserved. Comments and broken link reports welcomed.  
HTML; ?> */