Dotclear

Changeset 3924:6da65c37fbf6


Ignore:
Timestamp:
11/12/18 11:29:51 (7 years ago)
Author:
franck <carnet.franck.paul@…>
Branch:
default
Message:

Sanitize a little bit search string

File:
1 edited

Legend:

Unmodified
Added
Removed
  • inc/public/lib.urlhandlers.php

    r3874 r3924  
    241241            $GLOBALS['_search'] = !empty($_GET['q']) ? rawurldecode($_GET['q']) : ''; 
    242242            if ($GLOBALS['_search']) { 
     243                // Sanitize search string 
     244                $GLOBALS['_search'] = filter_var($GLOBALS['_search'], FILTER_SANITIZE_SPECIAL_CHARS); 
    243245                $params = new ArrayObject(['search' => $GLOBALS['_search']]); 
    244246                $core->callBehavior('publicBeforeSearchCount', $params); 
Note: See TracChangeset for help on using the changeset viewer.

Sites map