From 0e42f22c9ecf29579bcecee202d3f7b96263b070 Mon Sep 17 00:00:00 2001 From: Jaidyn Lev Date: Sat, 10 Nov 2018 14:02:10 -0600 Subject: [PATCH] Ridded of XSS flaw --- public_html/result/beam.php | 4 ++-- public_html/result/create.php | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/public_html/result/beam.php b/public_html/result/beam.php index 2cc8016..e9f251c 100644 --- a/public_html/result/beam.php +++ b/public_html/result/beam.php @@ -4,8 +4,8 @@ include("../../resources/library/main.php"); $item = strtolower($GLOBALS["file_beam_item"]); -$filename = $_GET["success"]; -$error = $_GET["error"]; +$filename = sanitize_filename($_GET["success"]); +$error = sanitize_filename($_GET["error"]); diff --git a/public_html/result/create.php b/public_html/result/create.php index c359342..3773e8d 100644 --- a/public_html/result/create.php +++ b/public_html/result/create.php @@ -4,8 +4,8 @@ include("../../resources/library/main.php"); $item = strtolower($GLOBALS["url_aliasize_item"]); -$filename = $_GET["success"]; -$error = $_GET["error"]; +$filename = sanitize_filename($_GET["success"]); +$error = sanitize_filename($_GET["error"]);