bug 1484: prevent XSS vulnerability, encode url.

improvement: no need to transmit the REQUEST_URI from PHP, Smarty already
knows it.

git-svn-id: http://piwigo.org/svn/trunk@5990 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
plegall
2010-04-29 10:44:30 +00:00
parent ba70c8f5cb
commit e7487082c3
4 changed files with 3 additions and 4 deletions
-1
View File
@@ -134,7 +134,6 @@ class BlockManager
global $template;
$template->set_filename('menubar', $file);
$template->assign(array('U_REDIRECT' => $_SERVER['REQUEST_URI']));
trigger_action('blockmanager_apply', array(&$this) );
foreach( $this->display_blocks as $id=>$block)