cvs: php-master-web /manage user-notes.php
| From: | Philip Olson | Date: | Tue, 27 May 2008 00:09:29 +0000 |
| Subject: | cvs: php-master-web /manage user-notes.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-1820@lists.php.net to get a copy of this message | ||
philip Tue May 27 00:09:29 2008 UTC
Modified files:
/php-master-web/manage user-notes.php
Log:
Escapes PHP_SELF (and defines as a constant)
http://cvs.php.net/viewvc.cgi/php-master-web/manage/user-notes.php?r1=1.67&r2=1.68&diff_format=u
Index: php-master-web/manage/user-notes.php
diff -u php-master-web/manage/user-notes.php:1.67 php-master-web/manage/user-notes.php:1.68
--- php-master-web/manage/user-notes.php:1.67 Mon May 26 23:50:04 2008
+++ php-master-web/manage/user-notes.php Tue May 27 00:09:29 2008
@@ -1,5 +1,5 @@
<?php
-// $Id: user-notes.php,v 1.67 2008/05/26 23:50:04 philip Exp $
+// $Id: user-notes.php,v 1.68 2008/05/27 00:09:29 philip Exp $
// Force login before action can be taken
include_once 'login.inc';
@@ -9,6 +9,7 @@
//require_once 'alert_lib.inc'; // remove comment if alerts are needed
define("NOTES_MAIL", "php-notes@lists.php.net");
+define("PHP_SELF", htmlentities($_SERVER['PHP_SELF'], ENT_QUOTES));
$reject_text =
'You are receiving this email because your note posted
@@ -118,7 +119,7 @@
?>
<p>Search the notes table.</p>
-<form method="post" action="<?php echo
$_SERVER['PHP_SELF'];?>">
+<form method="post" action="<?php echo PHP_SELF; ?>">
<table>
<tr>
<th align="right">Keyword or ID:</th>
@@ -132,10 +133,10 @@
</table>
</form>
-<p><a href="<?php echo
$_SERVER['PHP_SELF'];?>?action=mass">Mass change of
sections</a></p>
-<p><a href="<?php echo
$_SERVER['PHP_SELF'];?>?view=notes&type=0">View last 10
notes</a></p>
-<p><a href="<?php echo
$_SERVER['PHP_SELF'];?>?view=notes&type=1">View first 10
notes</a></p>
-<p><a href="<?php echo
$_SERVER['PHP_SELF'];?>?view=notes&type=2">View minor 10
notes</a></p>
+<p><a href="<?php echo PHP_SELF; ?>?action=mass">Mass change of
sections</a></p>
+<p><a href="<?php echo PHP_SELF; ?>?view=notes&type=0">View last 10
notes</a></p>
+<p><a href="<?php echo PHP_SELF; ?>?view=notes&type=1">View first
10 notes</a></p>
+<p><a href="<?php echo PHP_SELF; ?>?view=notes&type=2">View minor
10 notes</a></p>
<?php
foot();
exit;
@@ -181,7 +182,7 @@
$msg .= " to section <b>$_REQUEST[new_sect]</b>?";
echo "<p>$msg</p>\n";
?>
-<form action="<?php echo $_SERVER['PHP_SELF']; ?>?action=mass"
method="post">
+<form action="<?php echo PHP_SELF; ?>?action=mass" method="post">
<input type="hidden" name="step" value="2">
<input type="hidden" name="old_sect" value="<?php echo
$_REQUEST["old_sect"]; ?>">
<input type="hidden" name="ids" value="<?php echo
$_REQUEST["ids"]; ?>">
@@ -201,7 +202,7 @@
}
if ($step < 2) {
?>
-<form action="<?php echo $_SERVER['PHP_SELF']; ?>?action=mass"
method="post">
+<form action="<?php echo PHP_SELF; ?>?action=mass" method="post">
<input type="hidden" name="step" value="1">
<p>Change section of notes which fit these criteria:</p>
<table>
@@ -226,7 +227,7 @@
</form>
<?php
}
- echo "<p><a href='{$_SERVER['PHP_SELF']}'>Back to notes
index</a></p>\n";
+ echo "<p><a href='", PHP_SELF, "'>Back to notes
index</a></p>\n";
foot();
exit;
case 'approve':
@@ -323,7 +324,7 @@
stripslashes($email),"</span></p>";
}
?>
-<form method="post" action="<?php echo
$_SERVER['PHP_SELF'];?>">
+<form method="post" action="<?php echo PHP_SELF; ?>">
<input type="hidden" name="id" value="<?php echo $id;?>"
/>
<table>
<tr>