Revision 656
Added by thorn almost 18 years ago
| save.php | ||
|---|---|---|
| 40 | 40 | 
    }  | 
| 41 | 41 | 
     | 
| 42 | 42 | 
    // Gather details entered  | 
| 43 | 
    $group_name = $admin->get_post('group_name');
   | 
|
| 43 | 
    $group_name = $admin->get_post_escaped('group_name');
   | 
|
| 44 | 44 | 
     | 
| 45 | 45 | 
    // Create a javascript back link  | 
| 46 | 46 | 
    $js_back = "javascript: history.go(-1);";  | 
Also available in: Unified diff
Added some missing add_slashes(), get_post_escaped(), and strip_tags() for $_POST, $_GET and $_REQUEST-data. Also for $_SERVER['PHP_SELF'].