Show
Ignore:
Timestamp:
03/21/06 17:08:37 (3 years ago)
Author:
mbonetti
Message:

fixed another XSS

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/rss/admin/channels.php

    r1388 r1391  
    240240    case 'LBL_ADMIN_ADD': 
    241241    case 'Add': 
    242      
     242 
    243243        $label  = trim(sanitize($_REQUEST['new_channel'], RSS_SANITIZER_URL)); 
    244         $fid        = trim(sanitize($_REQUEST['add_channel_to_folder'], RSS_SANITIZER_SIMPLE_SQL | RSS_SANITIZER_NO_SPACES)); 
     244        $fid        = trim(sanitize($_REQUEST['add_channel_to_folder'], RSS_SANITIZER_NUMERIC)); 
    245245        list($flabel) = rss_fetch_row(rss_query( 
    246246          "select name from " . getTable('folders') . " where id=$fid"));