aboutsummaryrefslogtreecommitdiffstats
path: root/include/block.class.php
diff options
context:
space:
mode:
authorplegall <plg@piwigo.org>2010-04-29 10:44:30 +0000
committerplegall <plg@piwigo.org>2010-04-29 10:44:30 +0000
commite7487082c32de87efd756bf05ae8539d38cda373 (patch)
tree1f3c53b9fbb15fc576755f9af428b3a33178cf76 /include/block.class.php
parentba70c8f5cbd1f22c912a9b44363c246b6eb84dd7 (diff)
bug 1484: prevent XSS vulnerability, encode url.
improvement: no need to transmit the REQUEST_URI from PHP, Smarty already knows it. git-svn-id: http://piwigo.org/svn/trunk@5990 68402e56-0260-453c-a942-63ccdbb3a9ee
Diffstat (limited to '')
-rw-r--r--include/block.class.php1
1 files changed, 0 insertions, 1 deletions
diff --git a/include/block.class.php b/include/block.class.php
index af84330bd..e8f091741 100644
--- a/include/block.class.php
+++ b/include/block.class.php
@@ -134,7 +134,6 @@ class BlockManager
global $template;
$template->set_filename('menubar', $file);
- $template->assign(array('U_REDIRECT' => $_SERVER['REQUEST_URI']));
trigger_action('blockmanager_apply', array(&$this) );
foreach( $this->display_blocks as $id=>$block)