diff --git a/app/contacts/contact_addresses.php b/app/contacts/contact_addresses.php index 42a75d99db..48bc5ab0b6 100644 --- a/app/contacts/contact_addresses.php +++ b/app/contacts/contact_addresses.php @@ -17,22 +17,26 @@ The Initial Developer of the Original Code is Mark J Crane - Portions created by the Initial Developer are Copyright (C) 2008-2012 + Portions created by the Initial Developer are Copyright (C) 2008-2018 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ -require_once "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (permission_exists('contact_address_view')) { - //access granted -} -else { - echo "access denied"; - exit; -} + +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('contact_address_view')) { + //access granted + } + else { + echo "access denied"; + exit; + } //show the content echo "\n"; @@ -75,25 +79,25 @@ else { if ($result_count > 0) { foreach($result as $row) { - $map_query = $row['address_street']." ".$row['address_extended'].", ".$row['address_locality'].", ".$row['address_region'].", ".$row['address_region'].", ".$row['address_postal_code']; + $map_query = escape($row['address_street'])." ".escape($row['address_extended']).", ".escape($row['address_locality']).", ".escape($row['address_region']).", ".escape($row['address_region']).", ".escape($row['address_postal_code']); if (permission_exists('contact_address_edit')) { - $tr_link = "href='contact_address_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."'"; + $tr_link = "href='contact_address_edit.php?contact_uuid=".escape($row['contact_uuid'])."&id=".escape($row['contact_address_uuid'])."'"; } - echo "\n"; - echo " \n"; - echo " \n"; - echo " \n"; - echo " \n"; + echo "\n"; + echo " \n"; + echo " \n"; + echo " \n"; + echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; echo "\n"; @@ -104,4 +108,4 @@ else { echo "
".$row['address_label']." ".$row['address_street']." ".$row['address_locality'].(($row['address_locality'] != '' && $row['address_region'] != '') ? ", " : null).$row['address_region']." ".$row['address_country']." 
".escape($row['address_label'])." ".escape($row['address_street'])." ".escape($row['address_locality']).(($row['address_locality'] != '' && $row['address_region'] != '') ? ", " : null).escape($row['address_region'])." ".escape($row['address_country'])." ".$row['address_description']." ".escape($row['address_description'])." "; if (permission_exists('contact_address_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('contact_address_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo "
"; -?> \ No newline at end of file +?>