************************************************************************/
// Some security stuff...
-if (ereg(basename(__FILE__), $_SERVER['PHP_SELF']))
-{
+if (!defined('__SECURITY')) {
$INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
require($INC);
+} elseif ($BLOCK_MODE) {
+ // Block mode detected
+ return;
}
-if (GET_ACTION("guest", $GLOBALS['what']) == "admin")
-{
- // Only when one admin link is clicked...
- $INC = sprintf("%sinc/modules/guest/what-%s.php", PATH, $GLOBALS['what']);
- if (file_exists($INC))
- {
- // Ok, we finally load the guest action module
- include($INC);
- }
- else
- {
- ADD_FATAL(GUEST_404_ACTION_1.$GLOBALS['what'].GUEST_404_ACTION_2);
- }
+// Only when one admin link is clicked...
+$INC = sprintf("inc/modules/guest/what-%s.php", SQL_ESCAPE($GLOBALS['what']));
+if (INCLUDE_READABLE($INC)) {
+ // Ok, we finally load the guest action module
+ LOAD_INC($INC);
+} else {
+ addFatalMessage(getMessage('GUEST_404_ACTION'), $GLOBALS['what']);
}
+
//
?>