Changeset 431

Show
Ignore:
Timestamp:
05/20/06 15:52:02 (2 years ago)
Author:
Rickard
Message:

Fixed XSS vulnerability involving "redirect_url".

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/upload/login.php

    r257 r431  
    7979        pun_setcookie($user_id, $form_password_hash, $expire); 
    8080 
    81         redirect($_POST['redirect_url'], $lang_login['Login redirect']); 
     81        redirect(htmlspecialchars($_POST['redirect_url']), $lang_login['Login redirect']); 
    8282} 
    8383 
  • trunk/upload/misc.php

    r205 r431  
    121121                pun_mail($recipient_email, $mail_subject, $mail_message, '"'.str_replace('"', '', $pun_user['username']).'" <'.$pun_user['email'].'>'); 
    122122 
    123                 redirect($_POST['redirect_url'], $lang_misc['E-mail sent redirect']); 
     123                redirect(htmlspecialchars($_POST['redirect_url']), $lang_misc['E-mail sent redirect']); 
    124124        } 
    125125