Plugin Directory

Changeset 1395973


Ignore:
Timestamp:
04/14/2016 09:42:45 PM (10 years ago)
Author:
avdude
Message:

escaped html strings

File:
1 edited

Legend:

Unmodified
Added
Removed
  • event-registration/trunk/public/evr_public-confirmation.php

    r1395799 r1395973  
    178178    echo '<p align="left"><strong>'.__('Please verify your registration details:','evr_language').'</strong></p>';
    179179    echo '<table width="95%" border="0"><tr><td><strong>'.__('Event Name/Cost:','evr_language').'</strong></td><td>';
    180     echo $event_name.' - '.$item_display_cur.'&nbsp;'.$payment.'</td></tr><tr><td><strong>';
     180    echo esc_html($event_name).' - '.esc_html($item_display_cur).'&nbsp;'.esc_html($payment).'</td></tr><tr><td><strong>';
    181181    _e('Registering Name:','evr_language');
    182     echo '</strong></td><td>'.$attendee_name.'</td></tr><tr><td><strong>'.__('Email Address:','evr_language').'</strong></td><td>';
     182    echo '</strong></td><td>'.esc_html($attendee_name).'</td></tr><tr><td><strong>'.__('Email Address:','evr_language').'</strong></td><td>';
    183183    echo $email.'</td></tr><tr><td><strong>'.__('Number of Attendees:','evr_language');
    184     echo '</strong></td><td>'.$quantity.'</td></tr><tr><td><strong>'.__('Order Details:','evr_language').'</strong></td><td>';
     184    echo '</strong></td><td>'.esc_html($quantity).'</td></tr><tr><td><strong>'.__('Order Details:','evr_language').'</strong></td><td>';
    185185#Registration Type
    186186    if ($reg_type == "WAIT"){echo "WAIT LIST";}
     
    189189        for ($row = 0; $row < $row_count; $row++) {
    190190            if ($item_order[$row]['ItemQty'] >= "1"){
    191                 echo $item_order[$row]['ItemQty']." ".$item_order[$row]['ItemCat']."-".$item_order[$row]['ItemName']." ".$item_display_cur . '  ' . $item_order[$row]['ItemCost']."<br \>";
     191                echo esc_html($item_order[$row]['ItemQty'])." ".esc_html($item_order[$row]['ItemCat'])."-".esc_html($item_order[$row]['ItemName'])." "
     192                .esc_html($item_display_cur) . '  ' . esc_html($item_order[$row]['ItemCost'])."<br \>";
    192193                }
    193194        }
     
    196197    if ($use_coupon == "Y"){
    197198        if($coupon == $coupon_code) {
    198             echo '<td><strong>'.__('Coupon:','evr_language').'</strong></td><td>'.$coupon_code_price.'</td>';
     199            echo '<td><strong>'.__('Coupon:','evr_language').'</strong></td><td>'.esc_html($coupon_code_price).'</td>';
    199200        }
    200201        elseif ($coupon != $coupon_code) {
     
    209210    }
    210211    echo '<tr><td colspan="2"></td></tr><tr><td><strong>'.__('Event Name / Total Cost:','evr_language').'</strong></td><td>';
    211     echo $event_name.': '.$item_display_cur.'<strong>  '.number_format($payment,2).'</strong></td></tr></table>';
     212    echo esc_html($event_name).': '.esc_html($item_display_cur).'<strong>  '.esc_html(number_format($payment,2)).'</strong></td></tr></table>';
    212213    echo '<p align="left"><strong>';
    213214    if ($reg_type == "WAIT"){
     
    215216    }
    216217    if ($reg_type == "RGLR"){
    217         $type = __('You are registering for','evr_language')." ".$quantity." ".__('person(s).','evr_language')."   ".__('Please provide the first and last name of each person:','evr_language');
     218        $type = __('You are registering for','evr_language')." ".esc_html($quantity)." ".__('person(s).','evr_language')."   ".__('Please provide the first and last name of each person:','evr_language');
    218219    }
    219220    echo $type;
    220221    echo '</strong><br />';
    221     echo '<form id="attendee_confirm" class="evr_regform" method="post" action="';
    222     echo evr_permalink($company_options['evr_page_id']);
    223     echo '" onSubmit="mySubmit.disabled=true;return validateConfirmationForm(this)"><p>';
     222    echo '<form id="attendee_confirm" class="evr_regform" method="post" action="'.evr_permalink($company_options['evr_page_id']). '" onSubmit="';
     223    echo esc_js('mySubmit.disabled=true;return validateConfirmationForm(this)').'"><p>';
    224224    if ( $quantity >"0"){
    225225        echo '<div style="width:95%;">';
     
    227227        do {
    228228            $person = $i + 1;
    229             echo __('Attendee','evr_language').' #'.$person.'<br/>&nbsp;&nbsp;&nbsp;'.__('First Name','evr_language').
     229            echo __('Attendee','evr_language').' #'.esc_html($person).'<br/>&nbsp;&nbsp;&nbsp;'.__('First Name','evr_language').
    230230            ': <input name="attendee['.$i.'][first_name]"';
    231             if ($i == 0){ echo 'value ="'.$fname.'"';}
     231            if ($i == 0){ echo 'value ="'.esc_html($fname).'"';}
    232232            echo '/>';
    233233            echo '<br/>&nbsp;&nbsp;&nbsp;'.__('Last Name','evr_language').': <input name="attendee['.$i.'][last_name]"';
    234             if ($i == 0){ echo 'value ="'.$lname.'"';}
     234            if ($i == 0){ echo 'value ="'.esc_html($lname).'"';}
    235235            echo '/></br>';
    236236            ++$i;
Note: See TracChangeset for help on using the changeset viewer.