[Midnightbsd-cvs] mports: index.cgi: close up cross-scripting hole.

ctriv at midnightbsd.org ctriv at midnightbsd.org
Sat Mar 22 02:10:17 EDT 2008


Log Message:
-----------
close up cross-scripting hole.

Modified Files:
--------------
    mports/Tools/magus/www/data/magus:
        index.cgi (r1.13 -> r1.14)

-------------- next part --------------
Index: index.cgi
===================================================================
RCS file: /home/cvs/mports/Tools/magus/www/data/magus/index.cgi,v
retrieving revision 1.13
retrieving revision 1.14
diff -L Tools/magus/www/data/magus/index.cgi -L Tools/magus/www/data/magus/index.cgi -u -r1.13 -r1.14
--- Tools/magus/www/data/magus/index.cgi
+++ Tools/magus/www/data/magus/index.cgi
@@ -249,7 +249,10 @@
   } else {
     $where{status} = { '!=', 'untested' };
   }
-      
+
+  for (keys %where) {
+    delete $where{$_} if m/\W/;
+  }      
   
   my @ports = Magus::Port->search_where(\%where, { order_by => 'name' });
   


More information about the Midnightbsd-cvs mailing list