Project

General

Profile

« Previous | Next » 

Revision 396

Added by Matthias over 17 years ago

Fixed problem with Page Title has to be escaped (#287)

View differences:

index.php
164 164
				</td>
165 165
				<?php if($admin->get_permission('pages_modify') == true AND $can_modify == true) { ?>
166 166
				<td>
167
					<a href="<?php echo ADMIN_URL; ?>/pages/modify.php?page_id=<?php echo $page['page_id']; ?>" title="<?php echo $TEXT['MODIFY']; ?>"><?php echo ($page['page_title']); ?></a>
167
					<a href="<?php echo ADMIN_URL; ?>/pages/modify.php?page_id=<?php echo $page['page_id']; ?>" title="<?php echo $TEXT['MODIFY']; ?>"><?php echo (htmlentities($page['page_title'])); ?></a>				
168 168
				</td>
169 169
				<?php } else { ?>
170 170
				<td>
171
					<?php	echo ($page['page_title']); ?>
171
					<?php echo (htmlentities($page['page_title'])); ?>
172 172
				</td>
173 173
				<?php } ?>
174 174
				<td align="left" width="232">
175
					<font color="#999999"><?php echo ($page['menu_title']); ?></font>
175
					<font color="#999999"><?php echo (htmlentities($page['menu_title'])); ?></font>
176 176
				</td>
177 177
				<td align="center" valign="middle" width="90">
178 178
				<?php if($page['visibility'] == 'public') { ?>
......
460 460
			for($i = 1; $i <= $page['level']; $i++) { $title_prefix .= ' - '; }
461 461
				$template->set_var(array(
462 462
												'ID' => $page['page_id'],
463
												'TITLE' => ($title_prefix.$page['page_title'])
463
												'TITLE' => ($title_prefix.htmlentities($page['page_title']))
464 464
												)
465 465
										);
466 466
				if($can_modify == true) {

Also available in: Unified diff