Changeset 29571

Show
Ignore:
Timestamp:
01/19/08 10:48:39 (6 months ago)
Author:
GamerZ
Message:

Fixed XSS

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • wp-useronline/trunk/readme.html

    r23240 r29571  
    292292                                    <li>NEW: Use number_format_i18n() Instead</li> 
    293293                                    <li>FIXED: Should Use display_name Instead Of user_name If WP-Stats Is Not Installed</li> 
     294                                    <li>FIXED: XSS Vulnerability</li> 
    294295                              </ul> 
    295296                        </li> 
  • wp-useronline/trunk/wp-useronline.php

    r23240 r29571  
    8383      $current_user = wp_get_current_user(); 
    8484      if(!empty($_SERVER['HTTP_REFERER'])) { 
    85             $referral = addslashes(urlencode($_SERVER['HTTP_REFERER'])); 
     85            $referral = addslashes(urlencode(strip_tags($_SERVER['HTTP_REFERER']))); 
    8686      } 
    8787      // Check For Bot 
  • wp-useronline/trunk/wp-useronline.pot

    r23240 r29571  
    33"Project-Id-Version: WP-UserOnline 2.30\n" 
    44"POT-Creation-Date: \n" 
    5 "PO-Revision-Date: 2007-10-25 23:35+0800\n" 
     5"PO-Revision-Date: 2008-01-19 18:48+0800\n" 
    66"Last-Translator: Lester 'GaMerZ' Chan <gamerz84@hotmail.com>\n" 
    77"Language-Team: Lester Chan <gamerz84@hotmail.com>\n"