Changeset 1602

Show
Ignore:
Timestamp:
11/06/2006 11:51:29 PM (2 years ago)
Author:
robertb
Message:

XSS-Luecke geschlossen

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/error404.php

    r1510 r1602  
    66 $c['main'] = "<h2>".$l['err404_topic']."</h2>\n<p>".$l['err404_message']."</p>"; 
    77 $c['main'] .= '     <form id="searchform" action="'.JLOG_PATH.'/search.php"> 
    8       <p><input class="userdata" type="text" name="q" size="30" value="'.$_GET['url'].'" /> 
     8      <p><input class="userdata" type="text" name="q" size="30" value="'.htmlspecialchars($_GET['url']).'" /> 
    99         <input class="send" type="submit" value="'.$l['content_search'].'" /></p> 
    1010     </form>';