Changeset 1748

Show
Ignore:
Timestamp:
08/25/07 01:14:54 (14 months ago)
Author:
mbonetti
Message:

fix for #491 -- fix a couple possible XSS holes

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/gregarius/admin/channels.php

    r1745 r1748  
    885885    $res = rss_query($sql); 
    886886    list ($id, $title, $url, $siteurl, $parent, $descr, $icon, $mode, $daterefreshed, $dateadded) = rss_fetch_row($res); 
     887    $title = htmlentities($title,ENT_QUOTES); 
    887888    // get tags 
    888889    $sql = "select t.tag from " . getTable('tag')." t " 
     
    973974 
    974975    // Description 
    975     $descr = trim(strip_tags($descr)); 
     976    $descr = trim(htmlentities(strip_tags($descr), ENT_QUOTES)); 
    976977    echo "<p><label for=\"c_descr\">". __('Description:') ."</label>\n" 
    977978    ."<input type=\"text\" id=\"c_descr\" name=\"c_descr\" value=\"$descr\" /></p>\n";