fix xss attack
authorRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 05:08:33 +0000 (05:08 +0000)
committerRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 05:08:33 +0000 (05:08 +0000)
includes/OutputPage.php

index 0e8d533..f6a4a1a 100644 (file)
@@ -673,6 +673,7 @@ class OutputPage {
                if ( $returnto == NULL ) {
                        $returnto = $wgRequest->getText( 'returnto' );
                }
+               $returnto = htmlspecialchars( $returnto );
 
                $sk = $wgUser->getSkin();
                if ( '' == $returnto ) {