Sanitize HTML output from the 'showuser' command
authorArt Cancro <ajc@citadel.org>
Sun, 1 Jul 2007 04:20:36 +0000 (04:20 +0000)
committerArt Cancro <ajc@citadel.org>
Sun, 1 Jul 2007 04:20:36 +0000 (04:20 +0000)
webcit/userlist.c

index e74ab2305150772e1dda831f291b98b571398857..38539c0e1a6ed5b11b51f574fa487831a3d7e02d 100644 (file)
@@ -151,7 +151,9 @@ void showuser(void)
                urlescputs(who);
                wprintf("\">");
        }
-       wprintf("</td><td><h1>%s</h1></td></tr></table></center>\n", who);
+       wprintf("</td><td><h1>");
+       escputs(who);
+       wprintf("</h1></td></tr></table></center>\n");
        serv_printf("RBIO %s", who);
        serv_getln(buf, sizeof buf);
        if (buf[0] == '1') {