12 lines
641 B
Diff
12 lines
641 B
Diff
--- includes/system_footer.php.orig Tue Jul 31 10:35:50 2007
|
|
+++ includes/system_footer.php Tue Jul 31 10:35:52 2007
|
|
@@ -29,7 +29,7 @@
|
|
|
|
if( ! $hide_picklist ) {
|
|
echo "<center>\n";
|
|
- $update_form = "<form method=\"POST\" action=\"" . $_SERVER['PHP_SELF'] . "\">\n" . "\t" . $text['template'] . ": \n" . "\t<select name=\"template\">\n";
|
|
+ $update_form = "<form method=\"POST\" action=\"" . htmlentities(strip_tags($_SERVER['PHP_SELF'])) . "\">\n" . "\t" . $text['template'] . ": \n" . "\t<select name=\"template\">\n";
|
|
|
|
$resDir = opendir( APP_ROOT . '/templates/' );
|
|
while( false !== ( $strFile = readdir( $resDir ) ) ) {
|