cvs: pear /Pager Common.php package.xml
| From: | Lorenzo Alberton | Date: | Tue, 17 Aug 2004 14:45:57 +0000 |
| Subject: | cvs: pear /Pager Common.php package.xml | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-23009@lists.php.net to get a copy of this message | ||
quipo Tue Aug 17 10:45:57 2004 EDT
Modified files:
/pear/Pager Common.php package.xml
Log:
prevent XSS attaks
http://cvs.php.net/diff.php/pear/Pager/Common.php?r1=1.17&r2=1.18&ty=u
Index: pear/Pager/Common.php
diff -u pear/Pager/Common.php:1.17 pear/Pager/Common.php:1.18
--- pear/Pager/Common.php:1.17 Tue Aug 17 09:09:57 2004
+++ pear/Pager/Common.php Tue Aug 17 10:45:57 2004
@@ -33,7 +33,7 @@
// | Lorenzo Alberton <l.alberton at quipo.it> |
// +-----------------------------------------------------------------------+
//
-// $Id: Common.php,v 1.17 2004/08/17 13:09:57 quipo Exp $
+// $Id: Common.php,v 1.18 2004/08/17 14:45:57 quipo Exp $
/**
* File Common.php
@@ -60,7 +60,7 @@
*
* @author Richard Heyes <richard@phpguru.org>,
* @author Lorenzo Alberton <l.alberton at quipo.it>
- * @version $Id: Common.php,v 1.17 2004/08/17 13:09:57 quipo Exp $
+ * @version $Id: Common.php,v 1.18 2004/08/17 14:45:57 quipo Exp $
* @package Pager
*/
class Pager_Common
@@ -485,19 +485,19 @@
*
* @return mixed Next page ID
*/
- function getNextPageID()
- {
- return ($this->getCurrentPageID() == $this->numPages() ? false :
$this->getCurrentPageID() + 1);
- }
+ function getNextPageID()
+ {
+ return ($this->getCurrentPageID() == $this->numPages() ? false :
$this->getCurrentPageID() + 1);
+ }
- // }}}
+ // }}}
// {{{ getPreviousPageID()
/**
* Returns previous page ID. If current page is first page
- * this function returns FALSE
- *
- * @return mixed Previous pages' ID
+ * this function returns FALSE
+ *
+ * @return mixed Previous pages' ID
*/
function getPreviousPageID()
{
@@ -645,6 +645,7 @@
$querystring[] = $name . '=' . $value;
}
$querystring = array_merge($querystring, array_unique($arrays));
+ $querystring = array_map('htmlspecialchars', $querystring);
return '?' . implode('&', $querystring) . (!empty($querystring)
? '&' : '') . $this->_urlVar .'=';
}
http://cvs.php.net/diff.php/pear/Pager/package.xml?r1=1.27&r2=1.28&ty=u
Index: pear/Pager/package.xml
diff -u pear/Pager/package.xml:1.27 pear/Pager/package.xml:1.28
--- pear/Pager/package.xml:1.27 Sun Jul 18 03:39:19 2004
+++ pear/Pager/package.xml Tue Aug 17 10:45:57 2004
@@ -25,7 +25,7 @@
<release>
<version>2.2.3</version>
- <date>2004-07-18</date>
+ <date>2004-08-17</date>
<state>stable</state>
<notes>
<![CDATA[
@@ -35,6 +35,7 @@
"attribute" parameter to allow extra attributes for the select tag.
- added an example to show how this class can be used with big database
resultsets efficiently.
+- prevent XSS attacks (bug #2131), thanks to sou_sk at nifty dot com
]]>
</notes>
@@ -77,13 +78,17 @@
<changelog>
<release>
<version>2.2.3</version>
- <date>2004-07-18</date>
+ <date>2004-08-17</date>
<state>stable</state>
<notes>
<![CDATA[
-- array values given as GET parameters were not carried on (bug #1904)
+- just the last one of a set of array values given as GET parameters
+ (i.e. site.php?foo[]=1&foo[]=2&foo[]=3) was carried on (bug #1904).
- make 4th parameter of getPerPageSelectBox() an array, and add an
- "attribute" parameter to allow extra attributes for the select tag
+ "attribute" parameter to allow extra attributes for the select tag.
+- added an example to show how this class can be used with big database
+ resultsets efficiently.
+- prevent XSS attacks (bug #2131), thanks to sou_sk at nifty dot com
]]>
</notes>
</release>
@@ -99,7 +104,7 @@
* $showAllData (if true, an <option> to show
all the data is displayed in the generated <select>);
* $optionText (text to show in each <option>; use '%d' where you want to see
- the number of pages selected)
+ the number of pages selected)
- added showAllText option for alternate text in the $showAllData <option>
(the default is the number of total items).
- fixed getPageData() when $pageID is specified (bug #1377) (thanks to Ian Eure)