XSS protection
authorJamie Cameron <jcameron@webmin.com>
Fri, 15 Feb 2008 00:08:08 +0000 (00:08 +0000)
committerJamie Cameron <jcameron@webmin.com>
Fri, 15 Feb 2008 00:08:08 +0000 (00:08 +0000)
file/edit_html.cgi
file/upform.cgi

index 5d41ec0..a121ee7 100755 (executable)
@@ -1,6 +1,7 @@
 #!/usr/local/bin/perl
 # Show an HTML editor window
 
+$trust_unknown_referers = 1;
 require './file-lib.pl';
 do '../ui-lib.pl';
 $disallowed_buttons{'edit'} && &error($text{'ebutton'});
index dec684f..4fcaded 100755 (executable)
@@ -2,6 +2,7 @@
 # upform.cgi
 # Display the upload form
 
+$trust_unknown_referers = 1;
 require './file-lib.pl';
 $disallowed_buttons{'upload'} && &error($text{'ebutton'});
 &ReadParse(undef, undef, 1);