must escape config data
authorjeff <jeff>
Mon, 18 Jun 2007 16:46:20 +0000 (16:46 +0000)
committerjeff <jeff>
Mon, 18 Jun 2007 16:46:20 +0000 (16:46 +0000)
httemplate/edit/svc_www.cgi

index a9f97ff..6e2db8f 100644 (file)
@@ -43,7 +43,7 @@
 %
 %  $pkgnum=$cust_svc->pkgnum;
 %  $svcpart=$cust_svc->svcpart;
 %
 %  $pkgnum=$cust_svc->pkgnum;
 %  $svcpart=$cust_svc->svcpart;
-%  $config=$svc_www->config;
+%  $config=$cgi->escapeHTML($svc_www->config);
 %  
 %  $part_svc=qsearchs('part_svc',{'svcpart'=>$svcpart});
 %  die "No part_svc entry!" unless $part_svc;
 %  
 %  $part_svc=qsearchs('part_svc',{'svcpart'=>$svcpart});
 %  die "No part_svc entry!" unless $part_svc;