Merge pull request #438 from Th3R3p0/master

fixed reflected xss
This commit is contained in:
Claude 2017-09-29 14:45:15 +02:00 committed by GitHub
commit 6ea5cbf403
6 changed files with 7 additions and 6 deletions

View File

@ -43,7 +43,7 @@
</div>
<div class="control-group">
<div class="controls">
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>
</div>

View File

@ -48,7 +48,7 @@
<span class="instruction"><a href="#" id="enable_codemirror" data-lang-enablesynhl="<?php echo lang('paste_enablesynhl'); ?>" data-lang-disablesynhl="<?php echo lang('paste_disablesynhl'); ?>"></a></span>
</label>
<textarea id="code" name="code" cols="40" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" name="code" cols="40" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>
<?php if($this->config->item('enable_captcha') && $this->session->userdata('is_human') === null){ ?>

View File

@ -43,7 +43,7 @@
<span class="instruction"><a href="#" id="enable_codemirror" data-lang-enablesynhl="<?php echo lang('paste_enablesynhl'); ?>" data-lang-disablesynhl="<?php echo lang('paste_disablesynhl'); ?>"></a></span>
</label>
<textarea id="code" name="code" cols="40" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" name="code" cols="40" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>

View File

@ -50,7 +50,7 @@
</div>
<div class="control-group">
<div class="controls">
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>
</div>

View File

@ -50,7 +50,7 @@
</div>
<div class="control-group">
<div class="controls">
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" class="span12" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>
</div>

View File

@ -1,5 +1,6 @@

<?php echo validation_errors(); ?>
<?php echo "hello"; ?>
<div class="row">
<div class="col-12 col-sm-12 col-lg-12">
@ -49,7 +50,7 @@
</div>
<div class="control-group">
<div class="controls">
<textarea id="code" class="form-control" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo $paste_set; }?></textarea>
<textarea id="code" class="form-control" name="code" rows="20" tabindex="4"><?php if(isset($paste_set)){ echo htmlspecialchars($paste_set); }?></textarea>
</div>
</div>