From a6c8a8fe8ac03f4f36e5aaa7f7fb3bf0e11654f8 Mon Sep 17 00:00:00 2001 From: Herman van Rink Date: Fri, 5 Aug 2011 10:14:18 +0200 Subject: [PATCH] XSS fixes --- tbl_tracking.php | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/tbl_tracking.php b/tbl_tracking.php index b3ac4f322..1dc239704 100644 --- a/tbl_tracking.php +++ b/tbl_tracking.php @@ -288,17 +288,17 @@ if (isset($_REQUEST['snapshot'])) { ' . $field['Field'] . '' . "\n"; + echo '' . htmlspecialchars($field['Field']) . '' . "\n"; } else { - echo '' . $field['Field'] . '' . "\n"; + echo '' . htmlspecialchars($field['Field']) . '' . "\n"; } ?> - - - - - - + + + + + + - - + + - - - - - + + + + +