Merge pull request #2789 from annando/1609-escaping

Special characters should be escaped
This commit is contained in:
Tobias Diekershoff 2016-09-23 08:46:02 +02:00 committed by GitHub
commit 4caaeb9978
4 changed files with 5 additions and 5 deletions

View file

@ -988,7 +988,7 @@ function search($s,$id='search-box',$url='search',$save = false, $aside = true)
$a = get_app(); $a = get_app();
$values = array( $values = array(
'$s' => $s, '$s' => htmlspecialchars($s),
'$id' => $id, '$id' => $id,
'$action_url' => $url, '$action_url' => $url,
'$search_label' => t('Search'), '$search_label' => t('Search'),

View file

@ -10,7 +10,7 @@ function profile_init(&$a) {
$a->page['aside'] = ''; $a->page['aside'] = '';
if($a->argc > 1) if($a->argc > 1)
$which = $a->argv[1]; $which = htmlspecialchars($a->argv[1]);
else { else {
$r = q("select nickname from user where blocked = 0 and account_expired = 0 and account_removed = 0 and verified = 1 order by rand() limit 1"); $r = q("select nickname from user where blocked = 0 and account_expired = 0 and account_removed = 0 and verified = 1 order by rand() limit 1");
if(count($r)) { if(count($r)) {
@ -27,7 +27,7 @@ function profile_init(&$a) {
$profile = 0; $profile = 0;
if((local_user()) && ($a->argc > 2) && ($a->argv[2] === 'view')) { if((local_user()) && ($a->argc > 2) && ($a->argv[2] === 'view')) {
$which = $a->user['nickname']; $which = $a->user['nickname'];
$profile = $a->argv[1]; $profile = htmlspecialchars($a->argv[1]);
} }
else { else {
auto_redir($a, $which); auto_redir($a, $which);

View file

@ -17,7 +17,7 @@
<html> <html>
<head> <head>
<title><?php if(x($page,'title')) echo $page['title'] ?></title> <title><?php if(x($page,'title')) echo $page['title'] ?></title>
<meta request="<?php echo $_REQUEST['pagename'] ?> "> <meta request="<?php echo htmlspecialchars($_REQUEST['pagename']) ?> ">
<script>var baseurl="<?php echo $a->get_baseurl() ?>";</script> <script>var baseurl="<?php echo $a->get_baseurl() ?>";</script>
<script>var frio="<?php echo "view/theme/frio"; ?>";</script> <script>var frio="<?php echo "view/theme/frio"; ?>";</script>
<?php $baseurl = $a->get_baseurl(); ?> <?php $baseurl = $a->get_baseurl(); ?>

View file

@ -11,7 +11,7 @@
<head> <head>
<title><?php if(x($page,'title')) echo $page['title'] ?></title> <title><?php if(x($page,'title')) echo $page['title'] ?></title>
<meta name="viewport" content="initial-scale=1.0"> <meta name="viewport" content="initial-scale=1.0">
<meta request="<?php echo $_REQUEST['pagename'] ?> "> <meta request="<?php echo htmlspecialchars($_REQUEST['pagename']) ?> ">
<script>var baseurl="<?php echo $a->get_baseurl() ?>";</script> <script>var baseurl="<?php echo $a->get_baseurl() ?>";</script>
<script>var frio="<?php echo "view/theme/frio"; ?>";</script> <script>var frio="<?php echo "view/theme/frio"; ?>";</script>
<?php $baseurl = $a->get_baseurl(); ?> <?php $baseurl = $a->get_baseurl(); ?>