mirror of
https://gitlab.archlinux.org/archlinux/aurweb.git
synced 2025-02-03 10:43:03 +01:00
Package names and dep conditions can be specially crafted for an XSS attack. Properly sanitize these variables on the package details page. In addition, avoid including dep conditions as part of a package link. Signed-off-by: canyonknight <canyonknight@gmail.com> Signed-off-by: Lukas Fleischer <archlinux@cryptocrack.de> |
||
---|---|---|
.. | ||
stats | ||
account_details.php | ||
account_edit_form.php | ||
account_search_results.php | ||
actions_form.php | ||
footer.php | ||
header.php | ||
pkg_comment_form.php | ||
pkg_comments.php | ||
pkg_details.php | ||
pkg_search_form.php | ||
pkg_search_results.php | ||
search_accounts_form.php | ||
template.phps | ||
tu_details.php | ||
tu_list.php |