Escape client input, console output etc. before doing any echo.

Signed-off-by: D9ping <D9ping@users.noreply.github.com>
This commit is contained in:
D9ping
2018-08-04 01:58:34 +02:00
parent 6be3680f8f
commit 2b03fa316d
12 changed files with 221 additions and 201 deletions

View File

@@ -11,13 +11,13 @@ function DisplayThemeConfig(){
switch( $_COOKIE['theme'] ) {
case "custom.css":
$cselected = "selected";
$cselected = ' selected="selected"';
break;
case "hackernews.css":
$hselected = "selected";
$hselected = ' selected="selected"';
break;
case "terminal.css":
$tselected = "selected";
$tselected = ' selected="selected"';
break;
}
@@ -37,9 +37,9 @@ function DisplayThemeConfig(){
<div class="form-group col-md-6">
<label for="code"><?php echo _("Select a theme"); ?></label>
<select class="form-control" id="theme-select"><?php echo _("Select a Theme"); ?>
<option value="default" class="theme-link" <?php echo $cselected; ?>>RaspAP (default)</option>
<option value="default" class="theme-link"<?php echo $cselected; ?>>RaspAP (default)</option>
<option value="hackernews" class="theme-link"<?php echo $hselected; ?>>HackerNews</option>
<option value="terminal" class="theme-link" <?php echo $tselected; ?>>Terminal</option>
<option value="terminal" class="theme-link"<?php echo $tselected; ?>>Terminal</option>
</select>
</div>
</div>
@@ -59,5 +59,4 @@ function DisplayThemeConfig(){
</div><!-- /.row -->
<?php
}
?>