diff --git a/main/inc/lib/fckeditor/editor/plugins/ImageManager/manager.php b/main/inc/lib/fckeditor/editor/plugins/ImageManager/manager.php index 1018971406..7578aabc1b 100644 --- a/main/inc/lib/fckeditor/editor/plugins/ImageManager/manager.php +++ b/main/inc/lib/fckeditor/editor/plugins/ImageManager/manager.php @@ -19,6 +19,9 @@ $IMConfig['allow_upload']=false; } */ + //clean injection string (XSS) + $base_url_alt = str_replace('"','',$_GET['base_url_alt']); + ?> @@ -32,9 +35,8 @@ var thumbdir = ""; var base_url = "getBaseURL(); ?>"; - - //var base_url_alt= ""; - var base_url_alt= ""; + + var base_url_alt= ""; var server_name = "";