fix xss attack
authorRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 04:15:29 +0000 (04:15 +0000)
committerRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 04:15:29 +0000 (04:15 +0000)
includes/ImagePage.php

index f375c7f..6eda491 100644 (file)
@@ -76,7 +76,7 @@ class ImagePage extends Article {
                                }
                                $s = "<div class=\"fullImageLink\">" . $anchoropen .
                                     "<img border=\"0\" src=\"{$url}\" width=\"{$width}\" height=\"{$height}\" alt=\"" .
-                                    $wgRequest->getVal( 'image' )."\" />" . $anchorclose . "</div>";
+                                    htmlspecialchars( $wgRequest->getVal( 'image' ) )."\" />" . $anchorclose . "</div>";
                        } else {
                                $s = "<div class=\"fullMedia\">".$sk->makeMediaLink($this->img->getName(),"")."</div>";
                        }