Fix XSS vulnerability in "web/template/header.php".

Signed-off-by: Lukas Fleischer <archlinux@cryptocrack.de>
This commit is contained in:
Lukas Fleischer 2011-03-30 17:07:27 +02:00
parent 746c2b72b5
commit 0a625ae8ff

View file

@ -51,8 +51,8 @@
reset($SUPPORTED_LANGS);
foreach ($SUPPORTED_LANGS as $lang => $lang_name) {
print '<a href="'
. $_SERVER["PHP_SELF"]."?setlang=$lang\""
. " title=\"$lang_name\">"
. htmlspecialchars($_SERVER["PHP_SELF"], ENT_QUOTES)
."?setlang=$lang\" title=\"$lang_name\">"
. strtolower($lang) . "</a>\n";
}
?>