Changeset 7640

Show
Ignore:
Timestamp:
05/05/09 10:05:00 (3 years ago)
Author:
p_lindheimer
Message:

add ENT_QUOTES to htmlspecialchars filtering

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • freepbx/branches/2.5/amp_conf/htdocs/admin/config.php

    r7597 r7640  
    2020$display = isset($_REQUEST['display'])?$_REQUEST['display']:''; 
    2121if (isset($_REQUEST['extdisplay'])) { 
    22   $extdisplay = htmlspecialchars($_REQUEST['extdisplay']); 
     22  $extdisplay = htmlspecialchars($_REQUEST['extdisplay'],ENT_QUOTES); 
    2323  $_REQUEST['extdisplay'] = $extdisplay; 
    2424} else { 
     
    307307    foreach($possibilites as $possibility) { 
    308308      if ( isset($_REQUEST[$possibility]) && $_REQUEST[$possibility] != '' ) { 
    309         $itemid = htmlspecialchars($_REQUEST[$possibility]); 
     309        $itemid = htmlspecialchars($_REQUEST[$possibility], ENT_QUOTES); 
    310310        $_REQUEST[$possibility] = $itemid; 
    311311      }