Revision 656
Added by thorn almost 17 years ago
save.php | ||
---|---|---|
40 | 40 |
} |
41 | 41 |
|
42 | 42 |
// Gather details entered |
43 |
$group_name = $admin->get_post('group_name'); |
|
43 |
$group_name = $admin->get_post_escaped('group_name');
|
|
44 | 44 |
|
45 | 45 |
// Create a javascript back link |
46 | 46 |
$js_back = "javascript: history.go(-1);"; |
Also available in: Unified diff
Added some missing add_slashes(), get_post_escaped(), and strip_tags() for $_POST, $_GET and $_REQUEST-data. Also for $_SERVER['PHP_SELF'].