Fix for Trac#446: prevent XSS vulnerabilities

SVN:trunk[1564]
This commit is contained in:
Denis Flaven
2011-09-08 13:33:47 +00:00
parent c4db9cd84e
commit 9aca772209

View File

@@ -50,7 +50,7 @@ function DumpHiddenParams($oP, $aInteractive, $aParameters)
{
if (!in_array($sAttCode, $aInteractive))
{
$oP->Add("<input type=\"hidden\" name=\"attr_$sAttCode\" value=\"$value\">");
$oP->Add("<input type=\"hidden\" name=\"attr_$sAttCode\" value=\"".htmlentities($value)."\">");
}
}
}