Changeset 1696 for trunk/comments.php


Ignore:
Timestamp:
Jan 4, 2007, 12:28:09 AM (18 years ago)
Author:
rub
Message:

Fixed: HTML vulnerability (Cross Site Scripting)

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/comments.php

    r1677 r1696  
    194194
    195195    'F_ACTION'=>PHPWG_ROOT_PATH.'comments.php',
    196     'F_KEYWORD'=>@$_GET['keyword'],
    197     'F_AUTHOR'=>@$_GET['author'],
     196    'F_KEYWORD'=>@htmlentities($_GET['keyword']),
     197    'F_AUTHOR'=>@htmlentities($_GET['author']),
    198198
    199199    'U_HOME' => make_index_url(),
Note: See TracChangeset for help on using the changeset viewer.