Changeset 2031


Ignore:
Timestamp:
Jun 7, 2007, 8:52:40 PM (17 years ago)
Author:
rub
Message:

Resolved issue 0000702: Code Injection with picture comment

Merge BSF 2029:2030 into branch-1_7

Location:
branches/branch-1_7
Files:
4 edited

Legend:

Unmodified
Added
Removed
  • branches/branch-1_7/admin/comments.php

    r1932 r2031  
    163163      'ID' => $row['id'],
    164164      'TN_SRC' => $thumb,
    165       'AUTHOR' => $row['author'],
     165      'AUTHOR' => trigger_event('render_comment_author', $row['author']),
    166166      'DATE' => format_date($row['date'],'mysql_datetime',true),
    167167      'CONTENT' => trigger_event('render_comment_content',$row['content'])
  • branches/branch-1_7/comments.php

    r2013 r2031  
    412412        'TN_SRC' => $thumbnail_src,
    413413        'ALT' => $name,
    414         'AUTHOR' => $author,
     414        'AUTHOR' => trigger_event('render_comment_author', $author),
    415415        'DATE'=>format_date($comment['date'],'mysql_datetime',true),
    416416        'CONTENT'=>trigger_event('render_comment_content',$comment['content']),
  • branches/branch-1_7/include/common.inc.php

    r1903 r2031  
    244244add_event_handler('render_comment_content', 'htmlspecialchars');
    245245add_event_handler('render_comment_content', 'parse_comment_content');
     246add_event_handler('render_comment_author', 'strip_tags');
    246247trigger_action('init');
    247248?>
  • branches/branch-1_7/include/picture_comment.inc.php

    r1900 r2031  
    137137        'comments.comment',
    138138        array(
    139           'COMMENT_AUTHOR' => empty($row['author'])
     139          'COMMENT_AUTHOR' => trigger_event('render_comment_author',
     140            empty($row['author'])
    140141            ? $lang['guest']
    141             : $row['author'],
     142            : $row['author']),
    142143
    143144          'COMMENT_DATE' => format_date(
Note: See TracChangeset for help on using the changeset viewer.