Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Browse files

Sanitizing user input

  • Loading branch information...
commit 8f09299e2468dfc4f9ec72b05acf47de3ef9d1d7 1 parent c898a8a
@LukasReschke LukasReschke authored
Showing with 3 additions and 3 deletions.
  1. +2 −2 apps/gallery/lib/tiles.php
  2. +1 −1  apps/gallery/templates/index.php
View
4 apps/gallery/lib/tiles.php
@@ -141,7 +141,7 @@ public function getWidth() {
}
public function get() {
- $r = '<div class="title gallery_div">'.$this->stack_name.'</div>';
+ $r = '<div class="title gallery_div">'.htmlentities($this->stack_name).'</div>';
for ($i = 0; $i < count($this->tiles_array); $i++) {
$top = rand(-5, 5);
$left = rand(-5, 5);
@@ -168,7 +168,7 @@ public function getCount() {
}
public function getOnClickAction() {
- return 'javascript:openNewGal(\''.$this->stack_name.'\');';
+ return 'javascript:openNewGal(\''.htmlentities($this->stack_name).'\');';
}
private $tiles_array;
View
2  apps/gallery/templates/index.php
@@ -14,7 +14,7 @@
</style>
<script type="text/javascript">
-var root = "<?php echo $root; ?>";
+var root = "<?php echo htmlentities($root); ?>";
function explode(element) {
$('div', element).each(function(index, elem) {
Please sign in to comment.
Something went wrong with that request. Please try again.