From 3fbc92f61e1cf362982d3e9697bf5261868cbb2c Mon Sep 17 00:00:00 2001 From: rub Date: Thu, 7 Jun 2007 18:50:25 +0000 Subject: Resolved issue 0000702: Code Injection with picture comment git-svn-id: http://piwigo.org/svn/trunk@2030 68402e56-0260-453c-a942-63ccdbb3a9ee --- include/common.inc.php | 1 + include/picture_comment.inc.php | 5 +++-- 2 files changed, 4 insertions(+), 2 deletions(-) (limited to 'include') diff --git a/include/common.inc.php b/include/common.inc.php index 847a52b87..db7546da7 100644 --- a/include/common.inc.php +++ b/include/common.inc.php @@ -242,5 +242,6 @@ if (isset($conf['header_notes'])) // default event handlers add_event_handler('render_comment_content', 'htmlspecialchars'); add_event_handler('render_comment_content', 'parse_comment_content'); +add_event_handler('render_comment_author', 'strip_tags'); trigger_action('init'); ?> diff --git a/include/picture_comment.inc.php b/include/picture_comment.inc.php index cab49ffcf..6370544a7 100644 --- a/include/picture_comment.inc.php +++ b/include/picture_comment.inc.php @@ -136,9 +136,10 @@ SELECT id,author,date,image_id,content $template->assign_block_vars( 'comments.comment', array( - 'COMMENT_AUTHOR' => empty($row['author']) + 'COMMENT_AUTHOR' => trigger_event('render_comment_author', + empty($row['author']) ? l10n('guest') - : $row['author'], + : $row['author']), 'COMMENT_DATE' => format_date( $row['date'], -- cgit v1.2.3