|
25 | 25 | <div>
|
26 | 26 | <br/>
|
27 | 27 | <b><?php echo $this->t('Destination:') ?></b>
|
28 |
| - <span class="destinationUpload"><?php echo $this->defaultUploadLocationText ?></span> |
| 28 | + <span class="destinationUpload"><?php echo $this->escape($this->defaultUploadLocationText); ?></span> |
29 | 29 | <br/><br/>
|
30 | 30 |
|
31 | 31 | <div class="belowDestinationUpload" style="display: none;"></div>
|
32 |
| - <input type="hidden" name="parent" class="destinationId" value="<?php echo $this->defaultUploadLocation ?>"/> |
| 32 | + <input type="hidden" name="parent" class="destinationId" value="<?php echo $this->escape($this->defaultUploadLocation); ?>"/> |
33 | 33 | <br/>
|
34 | 34 | <input style="margin-left: 0;" class="browseMIDASLink globalButton" type="button" value="Choose location"/>
|
35 | 35 | <br/><br/>
|
|
63 | 63 | <param name="type" value="application/x-java-applet;version=1.5"/>
|
64 | 64 | <param name="background" value="ffffff"/>
|
65 | 65 | <param name="loglevel" value="WARNING"/>
|
66 |
| - <param name="sessionId" value="<?php echo session_id(); ?>"/> |
| 66 | + <param name="sessionId" value="<?php echo $this->escape(session_id()); ?>"/> |
67 | 67 | <param name="baseURL"
|
68 |
| - value="<?php echo $this->protocol.'://'.$this->host.$this->webroot ?>/javauploaddownload/upload/"/> |
69 |
| - <param name="webroot" value="<?php echo $this->protocol.'://'.$this->host.$this->webroot ?>"/> |
| 68 | + value="<?php echo $this->escape($this->protocol).'://'.$this->escape($this->host.$this->webroot); ?>/javauploaddownload/upload/"/> |
| 69 | + <param name="webroot" value="<?php echo $this->escape($this->protocol).'://'.$this->escape($this->host.$this->webroot); ?>"/> |
70 | 70 | <param name="apiURL"
|
71 |
| - value="<?php echo $this->protocol.'://'.$this->host.$this->webroot ?>/api/json?useSession&method="/> |
| 71 | + value="<?php echo $this->escape($this->protocol).'://'.$this->escape($this->host.$this->webroot); ?>/api/json?useSession&method="/> |
72 | 72 | <param name="daScript"
|
73 |
| - value="<?php echo $this->protocol.'://'.$this->host.$this->webroot ?>/modules/dicomanonymize/public/java/upload/DA.script"/> |
| 73 | + value="<?php echo $this->escape($this->protocol).'://'.$this->escape($this->host.$this->webroot); ?>/modules/dicomanonymize/public/java/upload/DA.script"/> |
74 | 74 | <param name="getUploadFileOffsetBaseURL" value="gethttpuploadoffset/"/>
|
75 | 75 | <param name="onSuccessfulUploadRedirectEnable" value="true"/>
|
76 | 76 | <param name="onSuccessRedirectURL" value="/item/"/>
|
|
0 commit comments