diff --git a/app/devices/devices.php b/app/devices/devices.php
index 8a4d17d3fd..93259b5f1d 100644
--- a/app/devices/devices.php
+++ b/app/devices/devices.php
@@ -204,7 +204,7 @@
if (permission_exists('device_export')) {
echo " \n";
}
- echo " \n";
+ echo " \n";
echo " \n";
echo " \n";
echo " \n";
@@ -249,7 +249,7 @@
echo "\n";
echo "
\n";
if ($_GET['show'] == "all" && permission_exists('device_all')) {
- echo " | ".$_SESSION['domains'][$row['domain_uuid']]['domain_name']." | \n";
+ echo " ".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])." | \n";
}
echo " \n";
- echo (permission_exists('device_edit')) ? "".format_mac($row['device_mac_address'])."" : format_mac($row['device_mac_address']);
+ echo (permission_exists('device_edit')) ? "".format_mac(escape($row['device_mac_address']))."" : format_mac(escape($row['device_mac_address']));
echo " | \n";
- echo " ".$row['device_label']." | \n";
+ echo " ".escape($row['device_label'])." | \n";
if ($device_alternate) {
echo " \n";
if (strlen($row['device_uuid_alternate']) > 0) {
- echo " ".$row['alternate_label']."\n";
+ echo " ".escape($row['alternate_label'])."\n";
}
echo " | \n";
}
- echo " ".$row['device_vendor']." | \n";
- echo " ".$row['device_template']." | \n";
- echo " ".$device_profile_name." | \n";
- echo " ".$text['label-'.$row['device_enabled']]." | \n";
- echo " ".$row['device_provisioned_date']." - ".$row['device_provisioned_method']." - ".$row['device_provisioned_ip']." | \n";
- echo " ".$row['device_description']." | \n";
+ echo " ".escape($row['device_vendor'])." | \n";
+ echo " ".escape($row['device_template'])." | \n";
+ echo " ".escape($device_profile_name)." | \n";
+ echo " ".$text['label-'.escape($row['device_enabled'])]." | \n";
+ echo " ".escape($row['device_provisioned_date'])." - ".escape($row['device_provisioned_method'])." - ".escape($row['device_provisioned_ip'])." | \n";
+ echo " ".escape($row['device_description'])." | \n";
echo " \n";
if (permission_exists('device_edit')) {
echo "$v_link_label_edit\n";
|