escape of file and log urls

This commit is contained in:
Timendum 2016-04-18 12:16:58 +02:00
parent d54c599c0e
commit cf2b30569f
2 changed files with 2 additions and 2 deletions

View file

@ -40,7 +40,7 @@
foreach($files as $f) foreach($files as $f)
{ {
echo "<tr>"; echo "<tr>";
echo "<td><a href=\"".$file->get_downloads_folder().'/'.$f["name"]."\" download>".$f["name"]."</a></td>"; echo "<td><a href=\"".urlencode($file->get_downloads_folder()).'/'.urlencode($f["name"])."\" download>".$f["name"]."</a></td>";
echo "<td>".$f["size"]."</td>"; echo "<td>".$f["size"]."</td>";
echo "<td><a href=\"./list.php?delete=".sha1($f["name"])."\" class=\"btn btn-danger btn-sm\">Delete</a></td>"; echo "<td><a href=\"./list.php?delete=".sha1($f["name"])."\" class=\"btn btn-danger btn-sm\">Delete</a></td>";
echo "</tr>"; echo "</tr>";

View file

@ -41,7 +41,7 @@
foreach($files as $f) foreach($files as $f)
{ {
echo "<tr>"; echo "<tr>";
echo "<td><a href=\"".$file->get_logs_folder().'/'.$f["name"]."\" target=\"_blank\">".$f["name"]."</a></td>"; echo "<td><a href=\"".urlencode($file->get_logs_folder()).'/'.urlencode($f["name"])."\" target=\"_blank\">".$f["name"]."</a></td>";
echo "<td>".$f["size"]."</td>"; echo "<td>".$f["size"]."</td>";
echo "<td><a href=\"./logs.php?delete=".sha1($f["name"])."\" class=\"btn btn-danger btn-sm\">Delete</a></td>"; echo "<td><a href=\"./logs.php?delete=".sha1($f["name"])."\" class=\"btn btn-danger btn-sm\">Delete</a></td>";
echo "</tr>"; echo "</tr>";