Browse Source

XSS security fix

Serghey Rodin 11 năm trước cách đây
mục cha
commit
ba913ba0e7

+ 1 - 1
web/templates/admin/list_dns_rec.html

@@ -78,7 +78,7 @@
                                     <td class="log" width="239px"><b><?php echo $data[$key]['RECORD'] ?></b></td>
                                     <td class="log-counter-value" width="57px"><?php echo $data[$key]['TYPE'] ?></td>
                                     <td class="log-counter-value" width="62px"><?php echo $data[$key]['PRIORITY'] ?></td>
-                                    <td class="log-counter-value" ><?php echo $data[$key]['VALUE'] ?></td>
+                                    <td class="log-counter-value" ><?php echo htmlspecialchars($data[$key]['VALUE'], ENT_QUOTES, 'UTF-8') ?></td>
                                 </tr>
                             </table>
                         </td>

+ 1 - 1
web/templates/user/list_dns_rec.html

@@ -76,7 +76,7 @@
                                     <td class="log" width="239px"><b><?php echo $data[$key]['RECORD'] ?></b></td>
                                     <td class="log-counter-value" width="57px"><?php echo $data[$key]['TYPE'] ?></td>
                                     <td class="log-counter-value" width="62px"><?php echo $data[$key]['PRIORITY'] ?></td>
-                                    <td class="log-counter-value" ><?php echo $data[$key]['VALUE'] ?></td>
+                                    <td class="log-counter-value" ><?php echo htmlspecialchars($data[$key]['VALUE'], ENT_QUOTES, 'UTF-8') ?></td>
                                 </tr>
                             </table>
                         </td>