Only use htmlspecialchars.

pull/193/head
Michael R Sweet 16 years ago
parent 63275d2fa9
commit f494371060
  1. 2
      www/phplib/globals.php

@ -34,7 +34,7 @@ $REMOTE_ADDR = $_SERVER["REMOTE_ADDR"];
// Handle PHP_SELF differently - we need to quote it properly...
if (array_key_exists("PHP_SELF", $_SERVER))
$PHP_SELF = htmlspecialchars(urlencode($_SERVER["PHP_SELF"]), ENT_QUOTES);
$PHP_SELF = htmlspecialchars($_SERVER["PHP_SELF"], ENT_QUOTES);
else
$PHP_SELF = "";

Loading…
Cancel
Save