Merge pull request #357 from yaplik/master

fix non-persistent XSS due inproper content escaping
This commit is contained in:
Michael Kaufmann
2016-06-03 16:29:28 +02:00

View File

@@ -302,7 +302,7 @@ if ($action == 'login') {
}
$lastqrystr = "";
if (isset($_REQUEST['qrystr']) && $_REQUEST['qrystr'] != "") {
$lastqrystr = strip_tags($_REQUEST['qrystr']);
$lastqrystr = htmlspecialchars($_REQUEST['qrystr'], ENT_QUOTES);
}
eval("echo \"" . getTemplate('login') . "\";");