Merge pull request #357 from yaplik/master
fix non-persistent XSS due inproper content escaping
This commit is contained in:
@@ -302,7 +302,7 @@ if ($action == 'login') {
|
|||||||
}
|
}
|
||||||
$lastqrystr = "";
|
$lastqrystr = "";
|
||||||
if (isset($_REQUEST['qrystr']) && $_REQUEST['qrystr'] != "") {
|
if (isset($_REQUEST['qrystr']) && $_REQUEST['qrystr'] != "") {
|
||||||
$lastqrystr = strip_tags($_REQUEST['qrystr']);
|
$lastqrystr = htmlspecialchars($_REQUEST['qrystr'], ENT_QUOTES);
|
||||||
}
|
}
|
||||||
|
|
||||||
eval("echo \"" . getTemplate('login') . "\";");
|
eval("echo \"" . getTemplate('login') . "\";");
|
||||||
|
|||||||
Reference in New Issue
Block a user