Merge pull request #357 from yaplik/master
fix non-persistent XSS due inproper content escaping
This commit is contained in:
@@ -302,7 +302,7 @@ if ($action == 'login') {
|
||||
}
|
||||
$lastqrystr = "";
|
||||
if (isset($_REQUEST['qrystr']) && $_REQUEST['qrystr'] != "") {
|
||||
$lastqrystr = strip_tags($_REQUEST['qrystr']);
|
||||
$lastqrystr = htmlspecialchars($_REQUEST['qrystr'], ENT_QUOTES);
|
||||
}
|
||||
|
||||
eval("echo \"" . getTemplate('login') . "\";");
|
||||
|
||||
Reference in New Issue
Block a user