tazbug rev 35

fix security hole & bug 43
author xfred222
date Wed Dec 19 17:37:44 2012 -0500 (2012-12-19)
parents 8ec2f574923b
children 291785fb21f7
files web/bugs.cgi
line diff
     1.1 --- a/web/bugs.cgi	Mon Dec 17 09:21:14 2012 -0500
     1.2 +++ b/web/bugs.cgi	Wed Dec 19 17:37:44 2012 -0500
     1.3 @@ -335,9 +335,9 @@
     1.4  	fi
     1.5  	js_log "Will write message in $bugdir/$id/msg.$count "
     1.6  	sed "s/$(echo -en '\r') /\n/g" > $bugdir/$id/msg.$count << EOT
     1.7 -USER="$USER"
     1.8 +USER='$(echo $(GET $USER) | sed -e "s/'/\&#39;/g; s/\\\n/<br\/>/g; s/\\\t/\&#09;/g; s/\%22/\"/g"  )'
     1.9  DATE="$date"
    1.10 -MSG="$(GET msg)"
    1.11 +MSG='$(echo $(GET msg) | sed -e "s/'/\&#39;/g; s/\\\n/<br\/>/g; s/\\\t/\&#09;/g; s/\%22/\"/g"  )'
    1.12  EOT
    1.13  }
    1.14  
    1.15 @@ -356,14 +356,14 @@
    1.16  	sed "s/$(echo -en '\r') /\n/g" > $bugdir/$count/bug.conf << EOT
    1.17  # SliTaz Bug configuration
    1.18  
    1.19 -BUG="$(GET bug)"
    1.20 +BUG='$(echo $(GET bug) | sed -e "s/'/\&#39;/g; s/\\\n/<br\/>/g; s/\\\t/\&#09;/g; s/\%22/\"/g"  )'
    1.21  STATUS="OPEN"
    1.22  PRIORITY="$(GET priority)"
    1.23  CREATOR="$USER"
    1.24  DATE="$date"
    1.25 -PKGS="$(GET pkgs)"
    1.26 +PKGS='$(echo $(GET pkgs) | sed -e "s/'/\&#39;/g; s/\\\n/<br\/>/g; s/\\\t/\&#09;/g; s/\%22/\"/g"  )''
    1.27  
    1.28 -DESC="$(GET desc)"
    1.29 +DESC='$(echo $(GET desc) | sed -e "s/'/\&#39;/g; s/\\\n/<br\/>/g; s/\\\t/\&#09;/g; s/\%22/\"/g"  )''
    1.30  EOT
    1.31  }
    1.32