diff --git a/app/destinations/destinations.php b/app/destinations/destinations.php index d71116094f..228401229d 100644 --- a/app/destinations/destinations.php +++ b/app/destinations/destinations.php @@ -123,7 +123,7 @@ //prepare to page the results $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 50; - $param = "&search=".$search; + $param = "&search=".escape($search); if ($_GET['show'] == "all" && permission_exists('destination_all')) { $param .= "&show=all"; } @@ -199,7 +199,7 @@ } } - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo " \n"; @@ -250,36 +250,36 @@ //echo " ".$row['dialplan_uuid']." \n"; echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; if ($_GET['show'] == "all" && permission_exists('destination_all')) { if (strlen($_SESSION['domains'][$row['domain_uuid']]['domain_name']) > 0) { - $domain = $_SESSION['domains'][$row['domain_uuid']]['domain_name']; + $domain = escape($_SESSION['domains'][$row['domain_uuid']]['domain_name']); } else { $domain = $text['label-global']; } - echo " ".$domain."\n"; + echo " ".escape($domain)."\n"; } - echo " ".$row['destination_type']." \n"; - echo " ".format_phone($row['destination_number'])." \n"; + echo " ".escape($row['destination_type'])." \n"; + echo " ".escape(format_phone($row['destination_number']))." \n"; //echo " ".$row['destination_number_regex']." \n"; - echo " ".$row['destination_context']." \n"; - //echo " ".$row['fax_uuid']." \n"; + echo " ".escape($row['destination_context'])." \n"; + //echo " ".escape($row['fax_uuid'])." \n"; if (permission_exists('outbound_caller_id_select')) { - echo " ".$row['destination_caller_id_name']." \n"; - echo " ".$row['destination_caller_id_number']." \n"; + echo " ".escape($row['destination_caller_id_name'])." \n"; + echo " ".escape($row['destination_caller_id_number'])." \n"; } - //echo " ".$row['destination_cid_name_prefix']." \n"; - //echo " ".$row['destination_app']." \n"; - //echo " ".$row['destination_data']." \n"; - //echo " ".$row['destination_record']." \n"; - //echo " ".$row['destination_accountcode']." \n"; - echo " ".$row['destination_enabled']." \n"; - echo " ".$row['destination_description']." \n"; + //echo " ".escape($row['destination_cid_name_prefix'])." \n"; + //echo " ".escape($row['destination_app'])." \n"; + //echo " ".escape($row['destination_data'])." \n"; + //echo " ".escape($row['destination_record'])." \n"; + //echo " ".escape($row['destination_accountcode'])." \n"; + echo " ".escape($row['destination_enabled'])." \n"; + echo " ".escape($row['destination_description'])." \n"; echo " "; if (permission_exists('destination_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('destination_delete')) { echo "";