tazbug rev 35
fix security hole & bug 43
author | xfred222 |
---|---|
date | Wed Dec 19 17:37:44 2012 -0500 (2012-12-19) |
parents | 8ec2f574923b |
children | 291785fb21f7 |
files | web/bugs.cgi |
line diff
1.1 --- a/web/bugs.cgi Mon Dec 17 09:21:14 2012 -0500 1.2 +++ b/web/bugs.cgi Wed Dec 19 17:37:44 2012 -0500 1.3 @@ -335,9 +335,9 @@ 1.4 fi 1.5 js_log "Will write message in $bugdir/$id/msg.$count " 1.6 sed "s/$(echo -en '\r') /\n/g" > $bugdir/$id/msg.$count << EOT 1.7 -USER="$USER" 1.8 +USER='$(echo $(GET $USER) | sed -e "s/'/\'/g; s/\\\n/<br\/>/g; s/\\\t/\	/g; s/\%22/\"/g" )' 1.9 DATE="$date" 1.10 -MSG="$(GET msg)" 1.11 +MSG='$(echo $(GET msg) | sed -e "s/'/\'/g; s/\\\n/<br\/>/g; s/\\\t/\	/g; s/\%22/\"/g" )' 1.12 EOT 1.13 } 1.14 1.15 @@ -356,14 +356,14 @@ 1.16 sed "s/$(echo -en '\r') /\n/g" > $bugdir/$count/bug.conf << EOT 1.17 # SliTaz Bug configuration 1.18 1.19 -BUG="$(GET bug)" 1.20 +BUG='$(echo $(GET bug) | sed -e "s/'/\'/g; s/\\\n/<br\/>/g; s/\\\t/\	/g; s/\%22/\"/g" )' 1.21 STATUS="OPEN" 1.22 PRIORITY="$(GET priority)" 1.23 CREATOR="$USER" 1.24 DATE="$date" 1.25 -PKGS="$(GET pkgs)" 1.26 +PKGS='$(echo $(GET pkgs) | sed -e "s/'/\'/g; s/\\\n/<br\/>/g; s/\\\t/\	/g; s/\%22/\"/g" )'' 1.27 1.28 -DESC="$(GET desc)" 1.29 +DESC='$(echo $(GET desc) | sed -e "s/'/\'/g; s/\\\n/<br\/>/g; s/\\\t/\	/g; s/\%22/\"/g" )'' 1.30 EOT 1.31 } 1.32