Added XSS prevention

This commit is contained in:
root 2008-11-24 12:43:19 +00:00
parent 16d7b35bae
commit 31c57ef051

View file

@ -23,7 +23,7 @@
$s = mysql_real_escape_string($_REQUEST['s']);
$id = mysql_real_escape_string(strip_tags($_REQUEST['id']));
echo "parent._ac_rpc('$id',";
echo "parent._ac_rpc('".sanitizeHTML($id)."',";
$bits = explode(",", $s);