Special characters should be escaped

This commit is contained in:
Michael Vogel 2016-09-23 06:29:02 +00:00
parent 4948460232
commit 3f35fed35a
3 changed files with 4 additions and 4 deletions

View file

@ -10,7 +10,7 @@ function profile_init(&$a) {
$a->page['aside'] = '';
if($a->argc > 1)
$which = $a->argv[1];
$which = htmlspecialchars($a->argv[1]);
else {
$r = q("select nickname from user where blocked = 0 and account_expired = 0 and account_removed = 0 and verified = 1 order by rand() limit 1");
if(count($r)) {
@ -27,7 +27,7 @@ function profile_init(&$a) {
$profile = 0;
if((local_user()) && ($a->argc > 2) && ($a->argv[2] === 'view')) {
$which = $a->user['nickname'];
$profile = $a->argv[1];
$profile = htmlspecialchars($a->argv[1]);
}
else {
auto_redir($a, $which);