diff --git a/apache/edit_defines.cgi b/apache/edit_defines.cgi index f10176283..0b6859e30 100755 --- a/apache/edit_defines.cgi +++ b/apache/edit_defines.cgi @@ -11,7 +11,8 @@ print $text{'defines_desc'},"

\n"; @defs = &get_httpd_defines(1); if (@defs) { print &text('defines_config', - "".join(" ", @defs).""),"

\n"; + "".&html_escape(join(" ", @defs)).""), + "

\n"; } print &ui_form_start("save_defines.cgi", "post"); diff --git a/apache/edit_global.cgi b/apache/edit_global.cgi index 5b5adb1e6..93df0561b 100755 --- a/apache/edit_global.cgi +++ b/apache/edit_global.cgi @@ -28,7 +28,7 @@ if ($in{'type'} == 6) { print &ui_hr(); print &ui_subheading($text{'global_mime'}); print "$text{'global_mimedesc'}

\n"; - @links = ( &ui_link("edit_gmime_type.cgi?file=$mfile", + @links = ( &ui_link("edit_gmime_type.cgi?file=".&urlize($mfile), $text{'global_add'}) ); print &ui_links_row(\@links); print &ui_columns_start([ $text{'global_type'}, @@ -41,7 +41,8 @@ if ($in{'type'} == 6) { if (/^\s*(\S+)\s*(.*)$/) { print &ui_columns_row([ &ui_link("edit_gmime_type.cgi?line=$line". - "&file=$mfile", $1), $2 ]); + "&file=".&urlize($mfile), &html_escape($1)), + &html_escape($2) ]); } $line++; }