Dotclear


Ignore:
Timestamp:
08/03/16 17:38:39 (9 years ago)
Author:
franck <carnet.franck.paul@…>
Branch:
default
Message:

Fix somes vulnerabilities in blogroll plugin, thanks Onur Yılmaz - Netsparker ( https://www.netsparker.com)

File:
1 edited

Legend:

Unmodified
Added
Removed
  • plugins/blogroll/index.php

    r3182 r3297  
    5959if (!empty($_POST['import_links_do'])) { 
    6060     foreach ($_POST['entries'] as $idx) { 
    61           $link_title = $_POST['title'][$idx]; 
    62           $link_href  = $_POST['url'][$idx]; 
    63           $link_desc  = $_POST['desc'][$idx]; 
     61          $link_title = html::escapeHTML($_POST['title'][$idx]); 
     62          $link_href  = html::escapeHTML($_POST['url'][$idx]); 
     63          $link_desc  = html::escapeHTML($_POST['desc'][$idx]); 
    6464          try { 
    6565               $blogroll->addLink($link_title,$link_href,$link_desc,''); 
     
    8282if (!empty($_POST['add_link'])) 
    8383{ 
    84      $link_title = $_POST['link_title']; 
    85      $link_href = $_POST['link_href']; 
    86      $link_desc = $_POST['link_desc']; 
    87      $link_lang = $_POST['link_lang']; 
     84     $link_title = html::escapeHTML($_POST['link_title']); 
     85     $link_href = html::escapeHTML($_POST['link_href']); 
     86     $link_desc = html::escapeHTML($_POST['link_desc']); 
     87     $link_lang = html::escapeHTML($_POST['link_lang']); 
    8888 
    8989     try { 
     
    101101if (!empty($_POST['add_cat'])) 
    102102{ 
    103      $cat_title = $_POST['cat_title']; 
     103     $cat_title = html::escapeHTML($_POST['cat_title']); 
    104104 
    105105     try { 
Note: See TracChangeset for help on using the changeset viewer.

Sites map