Changeset 1733

Show
Ignore:
Timestamp:
07/08/2008 08:28:09 PM (5 months ago)
Author:
jeena
Message:

added htmlspecialchars()

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/admin/blog.func.php

    r1731 r1733  
    317317            if(strpos($url, "?") === false)  $url .= "?"; 
    318318            else $url .= "&"; 
    319             $url .= session_name() . "=" . session_id(); 
     319            $url .= session_name() . "=" . htmlspecialchars(session_id()); 
    320320        } 
    321321        return $url; 
     
    327327function add_session_id_input_tag() { 
    328328        if(empty($_COOKIE[session_name()])) { 
    329             return "<input type='hidden' name='" . session_name() . "' value='" . session_id() . "' />"; 
     329            return "<input type='hidden' name='" . session_name() . "' value='" . htmlspecialchars(session_id()) . "' />"; 
    330330        } 
    331331}