From db04ee96064d1292f2f75f395e83ae8fb78168aa Mon Sep 17 00:00:00 2001 From: "Michael Kaufmann (d00p)" Date: Sat, 30 Jan 2010 15:52:53 +0000 Subject: [PATCH] escape html-entities in filetemplates_edit --- admin_templates.php | 1 + 1 file changed, 1 insertion(+) diff --git a/admin_templates.php b/admin_templates.php index 1cdfa355..ede113cb 100644 --- a/admin_templates.php +++ b/admin_templates.php @@ -367,6 +367,7 @@ elseif($action == 'edit' } else { + $row = htmlentities_array($row); eval("echo \"" . getTemplate("templates/filetemplates_edit") . "\";"); } }