diff --git a/lam/templates/3rdParty/pla/htdocs/add_attr_form.php b/lam/templates/3rdParty/pla/htdocs/add_attr_form.php index 52c54821..d12ea187 100644 --- a/lam/templates/3rdParty/pla/htdocs/add_attr_form.php +++ b/lam/templates/3rdParty/pla/htdocs/add_attr_form.php @@ -100,7 +100,7 @@ if (get_request('meth','REQUEST') != 'ajax') { echo ''; printf('',$app['server']->getIndex()); - printf('',$request['dn']); + printf('',htmlspecialchars($request['dn'])); echo ''; echo '',$app['server']->getIndex()); printf('',rawurlencode($request['dn'])); -printf('',$request['template']); -printf('',get_rdn($request['dn'])); +printf('',htmlspecialchars($request['template'])); +printf('',htmlspecialchars(get_rdn($request['dn']))); printf('',_('Rename')); echo ''; diff --git a/lam/templates/3rdParty/pla/htdocs/view_jpeg_photo.php b/lam/templates/3rdParty/pla/htdocs/view_jpeg_photo.php index d52501cc..372ab5b5 100644 --- a/lam/templates/3rdParty/pla/htdocs/view_jpeg_photo.php +++ b/lam/templates/3rdParty/pla/htdocs/view_jpeg_photo.php @@ -18,7 +18,7 @@ $request['dn'] = get_request('dn','GET'); $request['attr'] = strtolower(get_request('attr','GET',false,'jpegphoto')); $request['index'] = get_request('index','GET',false,0); $request['type'] = get_request('type','GET',false,'image/jpeg'); -$request['filename'] = get_request('filename','GET',false,sprintf('%s.jpg',get_rdn($request['dn'],true))); +$request['filename'] = get_request('filename','GET',false,sprintf('%s.jpg',htmlspecialchars(get_rdn($request['dn'],true)))); $request['location'] = get_request('location','GET',false,'ldap'); switch ($request['location']) {