Changeset 1696


Ignore:
Timestamp:
Jan 4, 2007, 12:28:09 AM (17 years ago)
Author:
rub
Message:

Fixed: HTML vulnerability (Cross Site Scripting)

Location:
trunk
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/admin/user_list.php

    r1620 r1696  
    478478
    479479    'F_ADD_ACTION' => $base_url,
    480     'F_USERNAME' => @$_GET['username'],
     480    'F_USERNAME' => @htmlentities($_GET['username']),
    481481    'F_FILTER_ACTION' => PHPWG_ROOT_PATH.'admin.php'
    482482    ));
  • trunk/comments.php

    r1677 r1696  
    194194
    195195    'F_ACTION'=>PHPWG_ROOT_PATH.'comments.php',
    196     'F_KEYWORD'=>@$_GET['keyword'],
    197     'F_AUTHOR'=>@$_GET['author'],
     196    'F_KEYWORD'=>@htmlentities($_GET['keyword']),
     197    'F_AUTHOR'=>@htmlentities($_GET['author']),
    198198
    199199    'U_HOME' => make_index_url(),
Note: See TracChangeset for help on using the changeset viewer.