Make WordPress Core

Ticket #13654: install-password-fix.patch

File install-password-fix.patch, 1.0 KB (added by johanee, 15 years ago)

Do not use stripslashes() on admin password when installing

  • wp-admin/install.php

    old new  
    183183                // Fill in the data we gathered
    184184                $weblog_title = isset( $_POST['weblog_title'] ) ? trim( stripslashes( $_POST['weblog_title'] ) ) : '';
    185185                $user_name = isset($_POST['user_name']) ? trim( stripslashes( $_POST['user_name'] ) ) : 'admin';
    186                 $admin_password = isset($_POST['admin_password']) ? trim( stripslashes( $_POST['admin_password'] ) ) : '';
    187                 $admin_password_check = isset($_POST['admin_password2']) ? trim( stripslashes( $_POST['admin_password2'] ) ) : '';
     186                $admin_password = isset($_POST['admin_password']) ? $_POST['admin_password'] : '';
     187                $admin_password_check = isset($_POST['admin_password2']) ? $_POST['admin_password2'] : '';
    188188                $admin_email  = isset( $_POST['admin_email']  ) ?trim( stripslashes( $_POST['admin_email'] ) ) : '';
    189189                $public       = isset( $_POST['blog_public']  ) ? (int) $_POST['blog_public'] : 0;
    190190                // check e-mail address