From 0fb5267d07af57243d08ecafad4b5bcbe6d34a11 Mon Sep 17 00:00:00 2001 From: JustAMacUser Date: Tue, 21 Apr 2020 20:52:19 -0400 Subject: [PATCH] During install, HTML encode POST data for forms. --- install/index.php | 60 +++++++++++++++++++++++------------------------ 1 file changed, 30 insertions(+), 30 deletions(-) mode change 100755 => 100644 install/index.php diff --git a/install/index.php b/install/index.php old mode 100755 new mode 100644 index b7aedf29d..ea88d1877 --- a/install/index.php +++ b/install/index.php @@ -234,28 +234,28 @@
- +
- +
- +
- + If needed
- + Usually 3306 for MySQL or 5432 for PostgreSQL
@@ -265,7 +265,7 @@
- +

@@ -336,7 +336,7 @@ $pdo = pdo_connect($DB_HOST, $DB_USER, $DB_PASS, $DB_NAME, $DB_TYPE, $DB_PORT); if (!$pdo) { - print_error("Unable to connect to database using specified parameters (driver: $DB_TYPE)."); + print_error("Unable to connect to database using specified parameters (driver: " . htmlspecialchars($DB_TYPE) . ")."); exit; } @@ -362,13 +362,13 @@
- - - - - - - + + + + + + +

@@ -382,13 +382,13 @@ - - - - - - - + + + + + + + @@ -440,16 +440,16 @@ - - - - - - - + + + + + + + "; - echo make_config($DB_TYPE, $DB_HOST, $DB_USER, $DB_NAME, $DB_PASS, - $DB_PORT, $SELF_URL_PATH); + echo htmlspecialchars(make_config($DB_TYPE, $DB_HOST, $DB_USER, $DB_NAME, $DB_PASS, + $DB_PORT, $SELF_URL_PATH)); print ""; ?>