mirror of
https://github.com/webmin/webmin.git
synced 2026-02-03 06:03:28 +00:00
Fix to filter out user passed page
[no-build]
This commit is contained in:
@@ -32,6 +32,7 @@ if ($gconfig{'loginbanner'} && $ENV{'HTTP_COOKIE'} !~ /banner=1/ &&
|
||||
print "Set-Cookie: banner=1; path=/\r\n";
|
||||
&PrintHeader();
|
||||
$url = $in{'page'};
|
||||
$url = &filter_javascript($url);
|
||||
open(BANNER, "<$gconfig{'loginbanner'}");
|
||||
while(<BANNER>) {
|
||||
s/LOGINURL/$url/g;
|
||||
|
||||
@@ -40,6 +40,7 @@ if ($gconfig{'loginbanner'} && $ENV{'HTTP_COOKIE'} !~ /banner=1/ &&
|
||||
print "Set-Cookie: banner=1; path=/".$sec."\r\n";
|
||||
&PrintHeader();
|
||||
$url = $in{'page'};
|
||||
$url = &filter_javascript($url);
|
||||
open(BANNER, "<$gconfig{'loginbanner'}");
|
||||
while(<BANNER>) {
|
||||
s/LOGINURL/$url/g;
|
||||
|
||||
Reference in New Issue
Block a user