Escape special chars when displaying filename template cookies.

This commit is contained in:
Michal Čihař
2009-03-24 08:55:07 +00:00
parent e67226a446
commit 184934bb10

View File

@@ -173,19 +173,19 @@ echo PMA_pluginGetJavascript($export_list);
echo ' value="'; echo ' value="';
if ($export_type == 'database') { if ($export_type == 'database') {
if (isset($_COOKIE) && !empty($_COOKIE['pma_db_filename_template'])) { if (isset($_COOKIE) && !empty($_COOKIE['pma_db_filename_template'])) {
echo $_COOKIE['pma_db_filename_template']; echo htmlspecialchars($_COOKIE['pma_db_filename_template']);
} else { } else {
echo $GLOBALS['cfg']['Export']['file_template_database']; echo $GLOBALS['cfg']['Export']['file_template_database'];
} }
} elseif ($export_type == 'table') { } elseif ($export_type == 'table') {
if (isset($_COOKIE) && !empty($_COOKIE['pma_table_filename_template'])) { if (isset($_COOKIE) && !empty($_COOKIE['pma_table_filename_template'])) {
echo $_COOKIE['pma_table_filename_template']; echo htmlspecialchars($_COOKIE['pma_table_filename_template']);
} else { } else {
echo $GLOBALS['cfg']['Export']['file_template_table']; echo $GLOBALS['cfg']['Export']['file_template_table'];
} }
} else { } else {
if (isset($_COOKIE) && !empty($_COOKIE['pma_server_filename_template'])) { if (isset($_COOKIE) && !empty($_COOKIE['pma_server_filename_template'])) {
echo $_COOKIE['pma_server_filename_template']; echo htmlspecialchars($_COOKIE['pma_server_filename_template']);
} else { } else {
echo $GLOBALS['cfg']['Export']['file_template_server']; echo $GLOBALS['cfg']['Export']['file_template_server'];
} }