Changeset 68 in subversion


Ignore:
Timestamp:
Oct 31, 2005 6:47:03 PM (8 years ago)
Author:
roundcube
Message:

Prevent from address book XSS

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/roundcubemail/program/steps/addressbook/save.inc

    r58 r68  
    3535      continue; 
    3636     
    37     $a_write_sql[] = sprintf("%s='%s'", $col, addslashes($_POST[$fname])); 
     37    $a_write_sql[] = sprintf("%s='%s'", $col, addslashes(strip_tags($_POST[$fname]))); 
    3838    } 
    3939 
     
    104104     
    105105    $a_insert_cols[] = $col; 
    106     $a_insert_values[] = sprintf("'%s'", addslashes($_POST[$fname])); 
     106    $a_insert_values[] = sprintf("'%s'", addslashes(strip_tags($_POST[$fname]))); 
    107107    } 
    108108     
Note: See TracChangeset for help on using the changeset viewer.