+/**
+ * Secures $_SERVER['PHP_SELF'] against attacks
+ *
+ * @return void
+ */
+function securePhpSelf () {
+ // Did it run before?
+ if (isset($GLOBALS['php_self_secured'])) {
+ // Please do not call this twice!
+ die('PHP_SELF is already secured. Please do not call ' . __FUNCTION__ . ' for your self.');
+ } // END - if
+
+ // Secure the string
+ $_SERVER['PHP_SELF'] = secureString($_SERVER['PHP_SELF']);
+
+ // Split it up into path and filename
+ $phpSelfDirectory = dirname($_SERVER['PHP_SELF']);
+ $phpSelfFile = basename($_SERVER['PHP_SELF']);
+
+ // Check for a .php inside the $phpSelfDirectory...
+ while (strpos($phpSelfDirectory, '.php') !== false) {
+ // Correct the dirname
+ $phpSelfDirectory = substr($phpSelfDirectory, 0, (strpos($phpSelfDirectory, '.php') + 4));
+ // Rewrite filename...
+ $phpSelfFile = basename($phpSelfDirectory);
+ // ... and dirname
+ $phpSelfDirectory = dirname($phpSelfDirectory);
+ } // END - while
+
+ // Put both together again and let's pray it is secured now...
+ $_SERVER['PHP_SELF'] = $phpSelfDirectory . '/' . $phpSelfFile;
+
+ // Did run...
+ $GLOBALS['php_self_secured'] = true;
+
+ // Remove uneccessary variables
+ unset($phpSelfDirectory);
+ unset($phpSelfFile);
+}