[SECURITY][BUGFIX] Remote Command Execution in Workspace Abstract Controller
authorHelmut Hummel <helmut.hummel@typo3.org>
Fri, 16 Dec 2011 08:43:43 +0000 (09:43 +0100)
committerOliver Hader <oliver@typo3.org>
Fri, 16 Dec 2011 09:07:03 +0000 (10:07 +0100)
Change-Id: I2d57a6fa5beee32fe0637ad0e4a1af558958004c
Fixes: #32571
Releases: 4.7,4.6,4.5
Reviewed-on: http://review.typo3.org/7298
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader
typo3/sysext/workspaces/Classes/Controller/AbstractController.php

index feeccf2..0bea351 100644 (file)
@@ -25,7 +25,7 @@
  *  This copyright notice MUST APPEAR in all copies of the script!
  ***************************************************************/
 
-require_once($GLOBALS['BACK_PATH'] . 'template.php');
+require_once(PATH_site . TYPO3_mainDir . 'template.php');
 
 /**
  * Abstract action controller.