[FIX] XSS Vulnerability

This commit is contained in:
Sebastian Grewe 2013-11-02 18:57:35 +01:00
parent 83ee00259f
commit d25cfb0001
7 changed files with 17 additions and 17 deletions

View File

@ -26,7 +26,7 @@
<form action="{$smarty.server.PHP_SELF}" method="POST" id='query'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='query'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action}">
<input type="text" class="pin" name="query" value="{$smarty.request.query|default:"%"}"> <input type="text" class="pin" name="query" value="{$smarty.request.query|default:"%"|escape}">
<input type="submit" class="submit small" value="Query"> <input type="submit" class="submit small" value="Query">
</form> </form>
{include file="global/block_footer.tpl"} {include file="global/block_footer.tpl"}

View File

@ -61,9 +61,9 @@
</table></td> </table></td>
<td class="right"> <td class="right">
<form action="{$smarty.server.PHP_SELF}" method="POST" id='search'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='search'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"}"> <input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"|escape}">
<input type="submit" class="submit small" value="Search"> <input type="submit" class="submit small" value="Search">
</form></td></tr> </form></td></tr>
</tbody></table> </tbody></table>

View File

@ -2,9 +2,9 @@
<br> <br>
<center> <center>
<form action="{$smarty.server.PHP_SELF}" method="POST" id='search'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='search'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"}"> <input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"|escape}">
<input type="submit" class="submit small" value="Search"> <input type="submit" class="submit small" value="Search">
</form> </form>
</center> </center>

View File

@ -100,7 +100,7 @@
<form action="{$smarty.server.PHP_SELF}" method="POST" id='query'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='query'>
<input type="hidden" name="page" value="{$smarty.request.page|escape}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action|escape}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="query" value="{$smarty.request.query|default:"%"}"> <input type="text" class="pin" name="query" value="{$smarty.request.query|default:"%"|escape}">
<input type="submit" value="Query" class="alt_btn"> <input type="submit" value="Query" class="alt_btn">
</form> </form>
</div> </div>

View File

@ -44,9 +44,9 @@
<footer> <footer>
<div class="submit_link"> <div class="submit_link">
<form action="{$smarty.server.PHP_SELF}" method="POST" id='search'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='search'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"}"> <input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"|escape}">
<input type="submit" value="Search" class="alt_btn"> <input type="submit" value="Search" class="alt_btn">
</form> </form>
</div> </div>

View File

@ -85,9 +85,9 @@
<footer> <footer>
<div class="submit_link"> <div class="submit_link">
<form action="{$smarty.server.PHP_SELF}" method="POST" id='search'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='search'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"}"> <input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"|escape}">
<input type="submit" value="Search" class="alt_btn"> <input type="submit" value="Search" class="alt_btn">
</form> </form>
</div> </div>

View File

@ -74,9 +74,9 @@
<footer> <footer>
<div class="submit_link"> <div class="submit_link">
<form action="{$smarty.server.PHP_SELF}" method="POST" id='search'> <form action="{$smarty.server.PHP_SELF}" method="POST" id='search'>
<input type="hidden" name="page" value="{$smarty.request.page}"> <input type="hidden" name="page" value="{$smarty.request.page|escape}">
<input type="hidden" name="action" value="{$smarty.request.action}"> <input type="hidden" name="action" value="{$smarty.request.action|escape}">
<input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"}"> <input type="text" class="pin" name="search" value="{$smarty.request.height|default:"%"|escape}">
<input type="submit" value="Search" class="alt_btn"> <input type="submit" value="Search" class="alt_btn">
</form> </form>
</div> </div>