From: Javier Bassi Date: Wed, 19 Oct 2011 01:47:38 +0000 (-0200) Subject: Escaping username and group names. X-Git-Url: https://iam.tj/gitweb/gitweb.cgi?p=webmin.git;a=commitdiff_plain;h=b002fbb96ee916f63984181a31d1942222a38161 Escaping username and group names. --- diff --git a/useradmin/my_group_chooser.cgi b/useradmin/my_group_chooser.cgi index f1c8108d..509e2169 100755 --- a/useradmin/my_group_chooser.cgi +++ b/useradmin/my_group_chooser.cgi @@ -142,8 +142,8 @@ else { foreach $u (&get_groups_list()) { if ($in{'group'} eq $u->[0]) { print "\n"; } else { print "\n"; } - print "$u->[0]\n"; - print "$u->[3] \n"; + print "".&html_escape($u->[0])."\n"; + print "".&html_escape($u->[3])." \n"; } print "\n"; &popup_footer();