Changeset 1460325
- Timestamp:
- 07/25/2016 04:46:42 PM (10 years ago)
- Location:
- formbuilder/trunk
- Files:
-
- 4 edited
-
extensions/formbuilder_xml_db_results.class.php (modified) (4 diffs)
-
html/options_default.inc.php (modified) (3 diffs)
-
php/formbuilder_admin_functions.php (modified) (6 diffs)
-
php/formbuilder_parser.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
formbuilder/trunk/extensions/formbuilder_xml_db_results.class.php
r1030489 r1460325 580 580 if(isset($_GET['searchQuery'])) 581 581 { 582 $searchQuery = $_GET['searchQuery'];582 $searchQuery = htmlentities($_GET['searchQuery']); 583 583 } 584 584 … … 671 671 if(isset($_GET['formSearchQuery']) AND $_GET['formSearchQuery'] != "") 672 672 { 673 $searchQuery = $_GET['formSearchQuery'];673 $searchQuery = htmlentities($_GET['formSearchQuery'], ENT_QUOTES); 674 674 $searchQuery = str_replace("\'", "", $searchQuery); 675 675 $searchQuery = str_replace("'", "", $searchQuery); … … 683 683 <div class='formHeadBox'> 684 684 <form name='formSearchBox' method='get' action=''> 685 <?php if(isset($_GET['page'])) { ?><input type="hidden" name="page" value="<?php echo $_GET['page']; ?>" /><?php } ?>686 <?php if(isset($_GET['fbaction'])) { ?><input type="hidden" name="fbaction" value="<?php echo $_GET['fbaction']; ?>" /><?php } ?>687 <?php if(isset($_GET['pageNumber'])) { ?><input type="hidden" name="pageNumber" value="<?php echo $_GET['pageNumber']; ?>" /><?php } ?>688 <?php if(isset($_GET['formFilterID'])) { ?><input type="hidden" name="formFilterID" value="<?php echo $_GET['formFilterID']; ?>" /><?php } ?>685 <?php if(isset($_GET['page'])) { ?><input type="hidden" name="page" value="<?php echo htmlentities($_GET['page']); ?>" /><?php } ?> 686 <?php if(isset($_GET['fbaction'])) { ?><input type="hidden" name="fbaction" value="<?php echo htmlentities($_GET['fbaction']); ?>" /><?php } ?> 687 <?php if(isset($_GET['pageNumber'])) { ?><input type="hidden" name="pageNumber" value="<?php echo htmlentities($_GET['pageNumber']); ?>" /><?php } ?> 688 <?php if(isset($_GET['formFilterID'])) { ?><input type="hidden" name="formFilterID" value="<?php echo htmlentities($_GET['formFilterID']); ?>" /><?php } ?> 689 689 <input type="text" name="formSearchQuery" value="<?php echo $searchQuery; ?>" helptext="Search..." /> 690 690 <input type="submit" name="submit" value="Find" /> … … 736 736 <option value='orphaned' <?php if(isset($_GET['formFilterID']) AND $_GET['formFilterID'] == 'orphaned') { ?>selected='selected'<?php } ?>>Show Orphaned Forms</option> 737 737 </select> 738 <?php if(isset($_GET['page'])) { ?><input type="hidden" name="page" value="<?php echo $_GET['page']; ?>" /><?php } ?>739 <?php if(isset($_GET['fbaction'])) { ?><input type="hidden" name="fbaction" value="<?php echo $_GET['fbaction']; ?>" /><?php } ?>740 <?php if(isset($_GET['pageNumber'])) { ?><input type="hidden" name="pageNumber" value="<?php echo $_GET['pageNumber']; ?>" /><?php } ?>741 <?php if(isset($_GET['formSearchQuery'])) { ?><input type="hidden" name="formSearchQuery" value="<?php echo $_GET['formSearchQuery']; ?>" /><?php } ?>738 <?php if(isset($_GET['page'])) { ?><input type="hidden" name="page" value="<?php echo htmlentities($_GET['page']); ?>" /><?php } ?> 739 <?php if(isset($_GET['fbaction'])) { ?><input type="hidden" name="fbaction" value="<?php echo htmlentities($_GET['fbaction']); ?>" /><?php } ?> 740 <?php if(isset($_GET['pageNumber'])) { ?><input type="hidden" name="pageNumber" value="<?php echo htmlentities($_GET['pageNumber']); ?>" /><?php } ?> 741 <?php if(isset($_GET['formSearchQuery'])) { ?><input type="hidden" name="formSearchQuery" value="<?php echo htmlentities($_GET['formSearchQuery']); ?>" /><?php } ?> 742 742 <input type="submit" name="submit" value="Go" /> 743 743 </form> -
formbuilder/trunk/html/options_default.inc.php
r906598 r1460325 34 34 ?> 35 35 <form class='formSearch' name="formSearch" method="GET" action="<?php echo FB_ADMIN_PLUGIN_PATH; ?>"> 36 <input name='page' type="hidden" value="<?php echo $_GET['page']; ?>" />37 <input name='pageNumber' type="hidden" value="<?php echo $_GET['pageNumber']; ?>" />36 <input name='page' type="hidden" value="<?php echo htmlentities($_GET['page']); ?>" /> 37 <input name='pageNumber' type="hidden" value="<?php echo htmlentities($_GET['pageNumber']); ?>" /> 38 38 <input name='formSearch' type="text" size="10" value="<?php echo $formSearch; ?>" /> 39 39 <input class='searchButton' name='Search' type="submit" value="Search" /> … … 115 115 116 116 if(isset($_GET['pageNumber'])) 117 $page = $_GET['pageNumber'];117 $page = htmlentities($_GET['pageNumber']); 118 118 else 119 119 $page = ""; … … 140 140 <div width='125' style='float: right; text-align: right;'> 141 141 <?php echo $nav; ?> 142 </ span>142 </div> 143 143 </th> 144 144 </tr> -
formbuilder/trunk/php/formbuilder_admin_functions.php
r910179 r1460325 24 24 function formbuilder_admin_alert($msg = '', $msg2 = '') 25 25 { 26 $msg = htmlentities($msg); 27 $msg2 = htmlentities($msg2); 26 28 if($msg2 AND $msg) echo "<div class='updated'><p><strong>$msg</strong><br/>$msg2</p></div>"; 27 29 elseif($msg) echo "<div class='updated'><p><strong>$msg</strong></p></div>"; … … 31 33 function formbuilder_admin_warning($msg = '', $msg2 = '') 32 34 { 35 $msg = htmlentities($msg); 36 $msg2 = htmlentities($msg2); 33 37 if($msg2 AND $msg) echo "<div class='error'><p><strong>$msg</strong><br/>$msg2</p></div>"; 34 38 elseif($msg) echo "<div class='error'><p><strong>$msg</strong></p></div>"; … … 83 87 // Allow for alternate systems to do something with the action. 84 88 // If nothing is returned, proceed with the regular built-in functions. 85 $result = apply_filters('formbuilder_display_options_page', $_GET['fbaction']);89 $result = apply_filters('formbuilder_display_options_page', htmlentities($_GET['fbaction'])); 86 90 if(!empty($result)) 87 91 return; 92 93 $entityFbId = htmlentities($_GET['fbid']); 88 94 89 95 switch($_GET['fbaction']) { … … 94 100 95 101 case "editForm": 96 formbuilder_options_editForm($ _GET['fbid']);102 formbuilder_options_editForm($entityFbId); 97 103 break; 98 104 99 105 case "exportForm": 100 formbuilder_options_exportForm($ _GET['fbid']);106 formbuilder_options_exportForm($entityFbId); 101 107 break; 102 108 … … 106 112 107 113 case "editFormObject": 108 formbuilder_options_editFormObject($ _GET['fbid']);114 formbuilder_options_editFormObject($entityFbId); 109 115 break; 110 116 111 117 case "copyForm": 112 formbuilder_options_copyForm($ _GET['fbid']);118 formbuilder_options_copyForm($entityFbId); 113 119 break; 114 120 115 121 case "removeForm": 116 formbuilder_options_removeForm($ _GET['fbid']);122 formbuilder_options_removeForm($entityFbId); 117 123 break; 118 124 … … 122 128 123 129 case "editResponse": 124 formbuilder_options_editResponse($ _GET['fbid']);130 formbuilder_options_editResponse($entityFbId); 125 131 break; 126 132 127 133 case "copyResponse": 128 formbuilder_options_copyResponse($ _GET['fbid']);134 formbuilder_options_copyResponse($entityFbId); 129 135 break; 130 136 131 137 case "removeResponse": 132 formbuilder_options_removeResponse($ _GET['fbid']);138 formbuilder_options_removeResponse($entityFbId); 133 139 formbuilder_options_default(); 134 140 break; -
formbuilder/trunk/php/formbuilder_parser.php
r1030489 r1460325 41 41 $field = $results[0]; 42 42 43 $field['value'] = trim( $_GET['val']);43 $field['value'] = trim(htmlentities($_GET['val'])); 44 44 45 45
Note: See TracChangeset
for help on using the changeset viewer.