From 8e8daf41abb1fb9863e482d8f4eae48abe60ca6b Mon Sep 17 00:00:00 2001 From: thomasb Date: Wed, 22 Nov 2006 11:42:37 +0000 Subject: Fixed XSS vulnerability (Bug #1484109) git-svn-id: https://svn.roundcube.net/trunk@382 208e9e7b-5314-0410-a742-e7e81cd9613c --- roundcubemail/program/include/main.inc | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'roundcubemail/program/include') diff --git a/roundcubemail/program/include/main.inc b/roundcubemail/program/include/main.inc index da449c64c..55336fd30 100644 --- a/roundcubemail/program/include/main.inc +++ b/roundcubemail/program/include/main.inc @@ -1063,7 +1063,13 @@ function get_input_value($fname, $source, $allow_html=FALSE, $charset=NULL) return $value; } - +/** + * Remove single and double quotes from given string + */ +function strip_quotes($str) +{ + return preg_replace('/[\'"]/', '', $str); +} // ************** template parsing and gui functions ************** -- cgit v1.2.3