Commit 36bb0e80 authored by Dave Cridland's avatar Dave Cridland

OF-836 CVE-2015-6972 rXSS in audit-policy.jsp

parent 340f0fc9
...@@ -245,7 +245,7 @@ ...@@ -245,7 +245,7 @@
</td> </td>
<td width="99%"> <td width="99%">
<input type="text" size="15" maxlength="50" name="maxTotalSize" <input type="text" size="15" maxlength="50" name="maxTotalSize"
value="<%= ((maxTotalSize != null) ? maxTotalSize : "") %>"> value="<%= ((maxTotalSize != null) ? StringUtils.escapeForXML(maxTotalSize) : "") %>">
<% if (errors.get("maxTotalSize") != null) { %> <% if (errors.get("maxTotalSize") != null) { %>
...@@ -263,7 +263,7 @@ ...@@ -263,7 +263,7 @@
</td> </td>
<td width="99%"> <td width="99%">
<input type="text" size="15" maxlength="50" name="maxFileSize" <input type="text" size="15" maxlength="50" name="maxFileSize"
value="<%= ((maxFileSize != null) ? maxFileSize : "") %>"> value="<%= ((maxFileSize != null) ? StringUtils.escapeForXML(maxFileSize) : "") %>">
<% if (errors.get("maxFileSize") != null) { %> <% if (errors.get("maxFileSize") != null) { %>
...@@ -281,7 +281,7 @@ ...@@ -281,7 +281,7 @@
</td> </td>
<td width="99%"> <td width="99%">
<input type="text" size="15" maxlength="50" name="maxDays" <input type="text" size="15" maxlength="50" name="maxDays"
value="<%= ((maxDays != null) ? maxDays : "") %>"> value="<%= ((maxDays != null) ? StringUtils.escapeForXML(maxDays) : "") %>">
<% if (errors.get("maxDays") != null) { %> <% if (errors.get("maxDays") != null) { %>
...@@ -299,7 +299,7 @@ ...@@ -299,7 +299,7 @@
</td> </td>
<td width="99%"> <td width="99%">
<input type="text" size="15" maxlength="50" name="logTimeout" <input type="text" size="15" maxlength="50" name="logTimeout"
value="<%= ((logTimeout != null) ? logTimeout : "") %>"> value="<%= ((logTimeout != null) ? StringUtils.escapeForXML(logTimeout) : "") %>">
<% if (errors.get("logTimeout") != null) { %> <% if (errors.get("logTimeout") != null) { %>
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment