Merge pull request #1589 from owncloud/use-sanitizeHTML

Use sanitizeHTML instead of stripslashes + htmlspecialchars
remotes/origin/stable5
Lukas Reschke 12 years ago
commit 32b1c7ad5d
  1. 5
      lib/helper.php

@ -436,8 +436,9 @@ class OC_Helper {
//FIXME: should also check for value validation (i.e. the email is an email).
public static function init_var($s, $d="") {
$r = $d;
if(isset($_REQUEST[$s]) && !empty($_REQUEST[$s]))
$r = stripslashes(htmlspecialchars($_REQUEST[$s]));
if(isset($_REQUEST[$s]) && !empty($_REQUEST[$s])) {
$r = OC_Util::sanitizeHTML($_REQUEST[$s]);
}
return $r;
}

Loading…
Cancel
Save