svn: /web/php-bugs/trunk/www/ bug.php
| From: | Jakub Vrana | Date: | Thu, 08 Dec 2011 09:11:29 +0000 |
| Subject: | svn: /web/php-bugs/trunk/www/ bug.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-12605@lists.php.net to get a copy of this message | ||
vrana Thu, 08 Dec 2011 09:11:29 +0000
Revision: http://svn.php.net/viewvc?view=revision&revision=320649
Log:
Avoid XSS
Changed paths:
U web/php-bugs/trunk/www/bug.php
Modified: web/php-bugs/trunk/www/bug.php
===================================================================
--- web/php-bugs/trunk/www/bug.php 2011-12-08 08:53:54 UTC (rev 320648)
+++ web/php-bugs/trunk/www/bug.php 2011-12-08 09:11:29 UTC (rev 320649)
@@ -1082,11 +1082,11 @@
if ($bug_id == 'PREVIEW') {
?>
-<form action="report.php?package=<?php
$_SESSION['bug_preview']['package_name']; ?>"
method="post">
+<form action="report.php?package=<?php
htmlspecialchars($_SESSION['bug_preview']['package_name']); ?>"
method="post">
<?php foreach($_SESSION['bug_preview'] as $k => $v) {
- echo "<input type='hidden' name='in[{$k}]' value='",
htmlentities($v, ENT_QUOTES, 'UTF-8'), "'/>";
+ echo "<input type='hidden' name='in[", htmlspecialchars($k,
ENT_QUOTES), "]' value='", htmlentities($v, ENT_QUOTES, 'UTF-8'),
"'/>";
}
- echo "<input type='hidden' name='captcha'
value='{$_SESSION['captcha']}'/>";
+ echo "<input type='hidden' name='captcha' value='",
htmlspecialchars($_SESSION['captcha'], ENT_QUOTES), "'/>";
?>
<input type='submit' value='Send bug report' /> <input
type='submit' name='edit_after_preview' value='Edit' />
</form>