Pached XSS

This commit is contained in:
pikami
2016-06-13 12:49:13 +00:00
parent 04a6be87a5
commit 3ca9efd71c
4 changed files with 7 additions and 7 deletions

View File

@@ -37,7 +37,7 @@
$user = GetUserByID($userID);
echo '
<li class="dropdown">
<a class="dropdown-toggle glyphicon glyphicon-user" data-toggle="dropdown" href="#"> '.$user[1].'<span class="caret"></span></a>
<a class="dropdown-toggle glyphicon glyphicon-user" data-toggle="dropdown" href="#"> '.htmlspecialchars($user[1], ENT_QUOTES, 'UTF-8').'<span class="caret"></span></a>
<ul class="dropdown-menu">
<li><a href="mypastes">My pastes</a></li>
<li><a href="logout">Logout</a></li>