]> Git repositories of Nishi - repoview.git/commitdiff
fix xss
authorNishi <nishi@nishi.boats>
Fri, 30 Aug 2024 05:19:25 +0000 (05:19 +0000)
committerNishi <nishi@nishi.boats>
Fri, 30 Aug 2024 05:19:25 +0000 (05:19 +0000)
git-svn-id: file:///raid/svn-personal/repoview/trunk@75 7e8b2a19-8934-dd40-8cb3-db22cdd5a80f

CGI/theme/modern.c

index c6e10bca556db4b1ef423e63de5bf6500cef71cf..16675d2e4ca1779b622a0e9b3485ea5cb3aeb216 100644 (file)
@@ -83,6 +83,8 @@ char* html_escape(const char* input) {
                        add_data(&r, "&lt;");
                } else if(input[i] == '>') {
                        add_data(&r, "&gt;");
+               } else if(input[i] == '&') {
+                       add_data(&r, "&amp;");
                } else {
                        cbuf[0] = input[i];
                        add_data(&r, cbuf);