diff --git a/web/template/footer.php b/web/template/footer.php index 435de5c7..0948f686 100644 --- a/web/template/footer.php +++ b/web/template/footer.php @@ -2,7 +2,7 @@ $ver"; + echo "
" . htmlspecialchars($ver) . "
"; } ?> diff --git a/web/template/header.php b/web/template/header.php index 73486b4d..91ee8065 100644 --- a/web/template/header.php +++ b/web/template/header.php @@ -2,9 +2,9 @@ "> + xml:lang="" lang=""> - AUR (<?php print $LANG; ?>)<?php if ($title != "") { print " - " . $title; } ?> + AUR (<?php print htmlspecialchars($LANG); ?>)<?php if ($title != "") { print " - " . htmlspecialchars($title); } ?> @@ -52,8 +52,8 @@ reset($SUPPORTED_LANGS); foreach ($SUPPORTED_LANGS as $lang => $lang_name) { print '" - . strtolower($lang) . "\n"; + ."?setlang=" . htmlspecialchars($lang, ENT_QUOTES) . "\" title=\"" . htmlspecialchars($lang_name, ENT_QUOTES) . "\">" + . htmlspecialchars(strtolower($lang)) . "\n"; } ?> diff --git a/web/template/pkg_details.php b/web/template/pkg_details.php index 880a6758..046f836b 100644 --- a/web/template/pkg_details.php +++ b/web/template/pkg_details.php @@ -69,7 +69,7 @@ $out_of_date_time = ($row["OutOfDateTS"] == 0) ? $msg : gmdate("r", intval($row[


- ' . $row['URL'] ?>
+ ' . htmlspecialchars($row['URL']) ?>

diff --git a/web/template/stats/updates_table.php b/web/template/stats/updates_table.php index a8cdf5aa..8da67320 100644 --- a/web/template/stats/updates_table.php +++ b/web/template/stats/updates_table.php @@ -11,7 +11,7 @@ "> - +