Fixed XSS.
authorTim Starling <tstarling@users.mediawiki.org>
Thu, 23 Apr 2009 14:38:03 +0000 (14:38 +0000)
committerTim Starling <tstarling@users.mediawiki.org>
Thu, 23 Apr 2009 14:38:03 +0000 (14:38 +0000)
includes/specials/SpecialUpload.php

index c084923..d8679cd 100644 (file)
@@ -1166,7 +1166,7 @@ wgUploadAutoFill = {$autofill};
                else {
                        $wgOut->addHTML(
                                "<input tabindex='2' type='text' name='wpDestFile' id='wpDestFile' size='60'
-                                               value='{$encDestName}' onchange='toggleFilenameFiller()' $destOnkeyup />"
+                                               value=\"{$encDestName}\" onchange='toggleFilenameFiller()' $destOnkeyup />"
                        );
                }