From 89406f36c20e4d785bfb35c68e87475329cfbaf5 Mon Sep 17 00:00:00 2001 From: thomascube Date: Wed, 16 Aug 2006 08:06:31 +0000 Subject: Fixed some XSS and SQL injection issues --- program/steps/error.inc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'program/steps/error.inc') diff --git a/program/steps/error.inc b/program/steps/error.inc index aa8036afe..2d87a9da4 100644 --- a/program/steps/error.inc +++ b/program/steps/error.inc @@ -53,7 +53,7 @@ else if ($ERROR_CODE==401) else if ($ERROR_CODE==404) { $__error_title = "REQUEST FAILED/FILE NOT FOUND"; - $request_url = $_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']; + $request_url = htmlentities($_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']); $__error_text = << Please contact your server-administrator. -- cgit v1.2.3