From 2bc73e2e36fefc3c1ee1b8e97e686c6729e58dcb Mon Sep 17 00:00:00 2001 From: Andy Staudacher Date: Mon, 31 Aug 2009 21:51:57 -0700 Subject: Fix XSS vectors in HTML attributes (mostly t() calls) --- modules/user/views/admin_users.html.php | 10 +++++----- modules/user/views/admin_users_group.html.php | 6 +++--- modules/user/views/login.html.php | 2 +- 3 files changed, 9 insertions(+), 9 deletions(-) (limited to 'modules/user') diff --git a/modules/user/views/admin_users.html.php b/modules/user/views/admin_users.html.php index 9455f9d9..c065e4b1 100644 --- a/modules/user/views/admin_users.html.php +++ b/modules/user/views/admin_users.html.php @@ -44,7 +44,7 @@
" class="gDialogLink gButtonLink right ui-icon-left ui-state-default ui-corner-all" - title=""> + title="for_html_attr() ?>"> @@ -67,8 +67,8 @@ user admin ? "admin" : "" ?>"> " - title="" - alt="name) ?>" + title="for_html_attr() ?>" + alt="name) ?>" width="20" height="20" /> name) ?> @@ -92,7 +92,7 @@ class="gDialogLink gButtonLink ui-state-default ui-corner-all ui-icon-left"> - " + for_html_attr() ?>" class="gButtonLink ui-state-disabled ui-corner-all ui-icon-left"> @@ -106,7 +106,7 @@
" class="gDialogLink gButtonLink right ui-icon-left ui-state-default ui-corner-all" - title=""> + title="for_html_attr() ?>"> diff --git a/modules/user/views/admin_users_group.html.php b/modules/user/views/admin_users_group.html.php index 8418ebc9..476e0817 100644 --- a/modules/user/views/admin_users_group.html.php +++ b/modules/user/views/admin_users_group.html.php @@ -3,11 +3,11 @@ name) ?> special): ?> id") ?>" - title=" $group->name)) ?>" + title=" $group->name))->for_html_attr() ?>" class="gDialogLink gButtonLink ui-state-default ui-corner-all"> - " + for_html_attr() ?>" class="gDialogLink gButtonLink ui-state-disabled ui-corner-all ui-icon-left"> @@ -22,7 +22,7 @@ $user->name, "group" => $group->name)) ?>"> + array("user" => $user->name, "group" => $group->name))->for_html_attr() ?>"> diff --git a/modules/user/views/login.html.php b/modules/user/views/login.html.php index 27431ce8..bb670d51 100644 --- a/modules/user/views/login.html.php +++ b/modules/user/views/login.html.php @@ -3,7 +3,7 @@ guest): ?>
  • " - title="" + title="for_html_attr() ?>" id="gLoginLink">
  • -- cgit v1.2.3