--- source.inc.php (revision 19) +++ source.inc.php (working copy) @@ -13,7 +13,7 @@ $vars['refer'] = $vars['page']; - if (!is_page($vars['page'])) + if (!is_page($vars['page']) || !check_readable($vars['page'],false,false)) { return array( 'msg'=>$_source_messages['msg_notfound'],