Uploaded image for project: 'Observium'
  1. Observium
  2. OBS-1152

Security fixes + other small fixes

    XMLWordPrintable

Details

    Description

      Attached patch escapes some more output show to user. Fixes XSS exploits.
      Also added a wrapper function (escape()) for the htmlspecialchars (long and boring to type..). Let me know if another name may be more suitable for the function. I did not change all the htmlspecialchars yet, waste of time if this does not get commited

      Other changes;
      Changed $_POST/GET into $vars in multiple files in html/
      Removed mres for place it was not needed or was redundant.
      Fixed a typo in generic_definition.inc.php
      Check if bill name is set when adding bill, if not don't add an empty entry to DB

      Attachments

        Activity

          People

            landy Mike Stupalov
            kentbjoh Kent Johannessen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: