diff options
author | plegall <plg@piwigo.org> | 2010-04-29 10:44:30 +0000 |
---|---|---|
committer | plegall <plg@piwigo.org> | 2010-04-29 10:44:30 +0000 |
commit | e7487082c32de87efd756bf05ae8539d38cda373 (patch) | |
tree | 1f3c53b9fbb15fc576755f9af428b3a33178cf76 /include/block.class.php | |
parent | ba70c8f5cbd1f22c912a9b44363c246b6eb84dd7 (diff) |
bug 1484: prevent XSS vulnerability, encode url.
improvement: no need to transmit the REQUEST_URI from PHP, Smarty already
knows it.
git-svn-id: http://piwigo.org/svn/trunk@5990 68402e56-0260-453c-a942-63ccdbb3a9ee
Diffstat (limited to '')
-rw-r--r-- | include/block.class.php | 1 |
1 files changed, 0 insertions, 1 deletions
diff --git a/include/block.class.php b/include/block.class.php index af84330bd..e8f091741 100644 --- a/include/block.class.php +++ b/include/block.class.php @@ -134,7 +134,6 @@ class BlockManager global $template; $template->set_filename('menubar', $file); - $template->assign(array('U_REDIRECT' => $_SERVER['REQUEST_URI'])); trigger_action('blockmanager_apply', array(&$this) ); foreach( $this->display_blocks as $id=>$block) |