From 3753b965e0f66dd2a26d9afcc30c3b0c06d32f98 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Tue, 5 Jun 2018 18:42:54 -0600 Subject: [PATCH] Update time_conditions.php --- app/time_conditions/time_conditions.php | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/app/time_conditions/time_conditions.php b/app/time_conditions/time_conditions.php index ab5f364332..dddaf31c8e 100644 --- a/app/time_conditions/time_conditions.php +++ b/app/time_conditions/time_conditions.php @@ -196,34 +196,34 @@ foreach($result as $row) { $app_uuid = $row['app_uuid']; - $tr_link = "href='".PROJECT_PATH."/app/time_conditions/time_condition_edit.php?id=".$row['dialplan_uuid'].(($app_uuid != '') ? "&app_uuid=".$app_uuid : null)."'"; + $tr_link = "href='".PROJECT_PATH."/app/time_conditions/time_condition_edit.php?id=".escape($row['dialplan_uuid']).(($app_uuid != '') ? "&app_uuid=".escape($app_uuid) : null)."'"; echo "\n"; if (permission_exists("time_condition_delete")) { - echo " \n"; - $dialplan_ids[] = 'checkbox_'.$row['dialplan_uuid']; + echo " \n"; + $dialplan_ids[] = 'checkbox_'.escape($row['dialplan_uuid']); } echo " "; if (permission_exists('time_condition_edit')) { - echo "".$row['dialplan_name'].""; + echo "".escape($row['dialplan_name']).""; } else { - echo $row['dialplan_name']; + echo escape($row['dialplan_name']); } echo " \n"; echo " ".((strlen($row['dialplan_number']) > 0) ? $row['dialplan_number'] : " ")."\n"; - echo " ".$row['dialplan_context']."\n"; - echo " ".$row['dialplan_order']."\n"; + echo " ".escape($row['dialplan_context'])."\n"; + echo " ".escape($row['dialplan_order'])."\n"; echo " "; - echo " ".ucwords($row['dialplan_enabled'])."\n"; + echo " ".ucwords(escape($row['dialplan_enabled']))."\n"; echo " \n"; echo " ".((strlen($row['dialplan_description']) > 0) ? $row['dialplan_description'] : " ")."\n"; echo " \n"; if (permission_exists('time_condition_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('time_condition_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n";