bug #3115519: fixed XSS on search
This commit is contained in:

committed by
Marc Delisle

parent
80766a95ca
commit
3756112c7f
@@ -1644,7 +1644,7 @@ function PMA_linkOrButton($url, $message, $tag_params = array(),
|
|||||||
$tmp = $tag_params;
|
$tmp = $tag_params;
|
||||||
$tag_params = array();
|
$tag_params = array();
|
||||||
if (!empty($tmp)) {
|
if (!empty($tmp)) {
|
||||||
$tag_params['onclick'] = 'return confirmLink(this, \'' . $tmp . '\')';
|
$tag_params['onclick'] = 'return confirmLink(this, \'' . PMA_escapeJsString($tmp) . '\')';
|
||||||
}
|
}
|
||||||
unset($tmp);
|
unset($tmp);
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user