summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorScott Ullrich <sullrich@pfsense.org>2008-11-25 04:02:55 +0000
committerScott Ullrich <sullrich@pfsense.org>2008-11-25 04:02:55 +0000
commite0bbaf4d634935d86cf53c36ab1fbf2d52b9e670 (patch)
tree7cf4a494a3c5b3d73e563b93278a032d34609476
parent4d59f5fa2641b111f6cedf1edf88d657c1c0da56 (diff)
downloadpfsense-e0bbaf4d634935d86cf53c36ab1fbf2d52b9e670.zip
pfsense-e0bbaf4d634935d86cf53c36ab1fbf2d52b9e670.tar.gz
Escape posted values
-rwxr-xr-xusr/local/www/interfaces.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/usr/local/www/interfaces.php b/usr/local/www/interfaces.php
index 55fb96f..08b3fca 100755
--- a/usr/local/www/interfaces.php
+++ b/usr/local/www/interfaces.php
@@ -1412,7 +1412,7 @@ $types = array("none" => "None", "static" => "Static", "dhcp" => "DHCP", "pppoe"
var descr = $('gatewaydescr').getValue();
gatewayip = $('gatewayip').getValue();
var url = "system_gateways_edit.php";
- var pars = 'interface=' + iface + '&name=' + name + '&descr=' + descr + '&gateway=' + gatewayip;
+ var pars = 'interface=' + escape(iface) + '&name=' + escape(name) + '&descr=' + escape(descr) + '&gateway=' + escape(gatewayip);
var myAjax = new Ajax.Request(
url,
{
OpenPOWER on IntegriCloud