summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorjim-p <jimp@pfsense.org>2010-11-12 12:29:53 -0500
committerjim-p <jimp@pfsense.org>2010-11-12 12:29:53 -0500
commit2bf0ada5ed126215de8f5cac33a75a1148744134 (patch)
treeffdbc11b918a56964e8c57acf90c3e980cc4b228
parentf01d8c4951c7319f0d06d43caa8b6ae35d2aa933 (diff)
downloadpfsense-2bf0ada5ed126215de8f5cac33a75a1148744134.zip
pfsense-2bf0ada5ed126215de8f5cac33a75a1148744134.tar.gz
Protect against XSS by someone broadcasting an HTML SSID... (better to be safe...)
-rwxr-xr-xusr/local/www/status_wireless.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/usr/local/www/status_wireless.php b/usr/local/www/status_wireless.php
index 0aa56ba..cc04bb3 100755
--- a/usr/local/www/status_wireless.php
+++ b/usr/local/www/status_wireless.php
@@ -115,7 +115,7 @@ display_top_tabs($tab_array);
/* Split by Mac address for the SSID Field */
$split = preg_split("/([0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f])/i", $state);
preg_match("/([0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f]\:[0-9a-f][[0-9a-f])/i", $state, $bssid);
- $ssid = $split[0];
+ $ssid = htmlspecialchars($split[0]);
$bssid = $bssid[0];
/* Split the rest by using spaces for this line using the 2nd part */
$split = preg_split("/[ ]+/i", $split[1]);
OpenPOWER on IntegriCloud