diff options
| author | Ivan Kohler <ivan@freeside.biz> | 2013-06-01 02:26:24 -0700 |
|---|---|---|
| committer | Ivan Kohler <ivan@freeside.biz> | 2013-06-01 02:26:24 -0700 |
| commit | e31e521e1dc88b3a936023e5e3f8b52de42bb78f (patch) | |
| tree | 53075043eaf06a3efeada2e9e9da3ac492ad9b27 | |
| parent | 049f013e7e6409edcc3997f2496784573be3de3e (diff) | |
fix XSS
| -rwxr-xr-x | httemplate/edit/cust_pkg.cgi | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/httemplate/edit/cust_pkg.cgi b/httemplate/edit/cust_pkg.cgi index dd1ed335f..e6a7d4b71 100755 --- a/httemplate/edit/cust_pkg.cgi +++ b/httemplate/edit/cust_pkg.cgi @@ -34,7 +34,7 @@ <TR> <TD><INPUT TYPE="checkbox" NAME="remove_pkg" VALUE="<% $pkgnum %>"<% $checked %>></TD> <TD ALIGN="right"><% $pkgnum %>:</TD> - <TD><% $all_pkg{$pkgpart} %> - <% $all_comment{$pkgpart} %></TD> + <TD><% $all_pkg{$pkgpart} |h %> - <% $all_comment{$pkgpart} |h %></TD> </TR> % } @@ -79,7 +79,7 @@ Order new packages <INPUT TYPE="text" NAME="<% "pkg$pkgpart" %>" VALUE="<% $value %>" SIZE="2" MAXLENGTH="2"> </TD> <TD ALIGN="right"><% $pkgpart %>:</TD> - <TD><% $pkg{$pkgpart} %> - <% $comment{$pkgpart}%></TD> + <TD><% $pkg{$pkgpart} |h %> - <% $comment{$pkgpart} |h %></TD> </TR> % % $count ++ ; |
