From 9369ccab7fb3413d63e218cec81b4cf43442fd98 Mon Sep 17 00:00:00 2001 From: Bharat Mediratta Date: Sun, 31 May 2009 01:02:51 -0700 Subject: Run all variables that come from user-entered data through p::clean() --- modules/user/views/admin_users.html.php | 8 ++++---- modules/user/views/admin_users_group.html.php | 12 ++++++++---- modules/user/views/login.html.php | 2 +- modules/user/views/reset_password.html.php | 23 ++++++++++++----------- 4 files changed, 25 insertions(+), 20 deletions(-) (limited to 'modules/user') diff --git a/modules/user/views/admin_users.html.php b/modules/user/views/admin_users.html.php index bec74d28..859f3c8e 100644 --- a/modules/user/views/admin_users.html.php +++ b/modules/user/views/admin_users.html.php @@ -68,16 +68,16 @@ " title="" - alt="name ?>" + alt="name) ?>" width="20" height="20" /> - name ?> + name) ?> - full_name ?> + full_name) ?> - email ?> + email) ?> last_login == 0) ? "" : date("j-M-y", $user->last_login) ?> diff --git a/modules/user/views/admin_users_group.html.php b/modules/user/views/admin_users_group.html.php index a25e687a..820b3031 100644 --- a/modules/user/views/admin_users_group.html.php +++ b/modules/user/views/admin_users_group.html.php @@ -1,8 +1,8 @@ -name ?> +name) ?> special): ?> id") ?>" - title="name) ?>" + title=" p::clean($group->name))) ?>" class="gDialogLink gButtonLink ui-state-default ui-corner-all"> @@ -13,11 +13,15 @@