aboutsummaryrefslogtreecommitdiffstats
path: root/functions/init
diff options
context:
space:
mode:
authorJason Oster <parasytic@users.sourceforge.net>2009-02-13 20:52:28 +0000
committerJason Oster <parasytic@users.sourceforge.net>2009-02-13 20:52:28 +0000
commitf6da67d1980df72e6442f6014012a88103e100ba (patch)
tree5dce8684754d35d3081c51c07317b192bfc368dc /functions/init
parent665b2657ec42ddcc4bdfcc8fab24de56cab511ca (diff)
downloadphpicalendar-f6da67d1980df72e6442f6014012a88103e100ba.tar.gz
phpicalendar-f6da67d1980df72e6442f6014012a88103e100ba.tar.bz2
phpicalendar-f6da67d1980df72e6442f6014012a88103e100ba.zip
Fix potential XSS issue
Diffstat (limited to 'functions/init')
-rw-r--r--functions/init/sanitize.php16
1 files changed, 16 insertions, 0 deletions
diff --git a/functions/init/sanitize.php b/functions/init/sanitize.php
index db21021..5d72cad 100644
--- a/functions/init/sanitize.php
+++ b/functions/init/sanitize.php
@@ -32,6 +32,22 @@ function recursiveSanitize($value) {
return $value;
}
+
+function sanitizeForWeb($string) {
+ $string = preg_replace('/<br\s*\/?>/', "\n", $string);
+
+ $string = str_replace('&', '&amp;', $string);
+ $string = str_replace('<', '&lt;', $string);
+ $string = str_replace('>', '&gt;', $string);
+ $string = str_replace('\'', '&#39;', $string);
+ $string = str_replace('"', '&#34;', $string);
+
+ $string = str_replace('<br />', "\n", $string);
+
+ return $string;
+}
+
+
if (!isset($_SERVER) && isset($HTTP_SERVER_VARS)) {
$_SERVER = &$HTTP_SERVER_VARS;
}

© 2014-2024 Faster IT GmbH | imprint | privacy policy