diff options
| author | Andy Staudacher <andy.st@gmail.com> | 2009-08-29 15:41:02 -0700 |
|---|---|---|
| committer | Andy Staudacher <andy.st@gmail.com> | 2009-08-29 15:41:02 -0700 |
| commit | 0204617b602183a3e157bc7e23c617acd22a5212 (patch) | |
| tree | 429a7f7ecd3eb9e7cc846bbf5a4f28601e09d22d /modules/server_add/views/admin_server_add.html.php | |
| parent | c4d5ecde66c7bffde2259b9815c050e6a4d8f333 (diff) | |
XSS fixes
Diffstat (limited to 'modules/server_add/views/admin_server_add.html.php')
| -rw-r--r-- | modules/server_add/views/admin_server_add.html.php | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/modules/server_add/views/admin_server_add.html.php b/modules/server_add/views/admin_server_add.html.php index 30ab3536..c4439bda 100644 --- a/modules/server_add/views/admin_server_add.html.php +++ b/modules/server_add/views/admin_server_add.html.php @@ -11,12 +11,12 @@ <ul id="gPathList"> <? foreach ($paths as $id => $path): ?> <li class="ui-icon-left"> - <a href="<?= url::site("admin/server_add/remove_path?path=$path&csrf=$csrf") ?>" + <a href="<?= url::site("admin/server_add/remove_path?path=" . urlencode($path) . "&csrf=$csrf") ?>" id="icon_<?= $id?>" class="gRemoveDir ui-icon ui-icon-trash"> X </a> - <?= $path ?> + <?= SafeString::of($path) ?> </li> <? endforeach ?> </ul> |
