Skip to content

Commit

Permalink
fix: xss vulnerability
Browse files Browse the repository at this point in the history
:). Thanks again to @Chri060
  • Loading branch information
TheTipo01 committed Nov 22, 2024
1 parent 3ee73be commit fc46814
Showing 1 changed file with 4 additions and 11 deletions.
15 changes: 4 additions & 11 deletions website/index.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
<head>
<title>Inceneritore</title>
<meta charset="utf-8">
<meta content="width=device-width,initial-scale=1"name="viewport">
<link href="css/bootstrap.min.css"rel="stylesheet">
<meta content="width=device-width,initial-scale=1" name="viewport">
<link href="css/bootstrap.min.css" rel="stylesheet">
</head>
<body>
<div class="container">
Expand All @@ -22,10 +22,7 @@
$result = mysqli_query($connection, $query);
if (mysqli_num_rows($result) != 0) {
while ($row = mysqli_fetch_array($result)) {
echo "<tr>";
echo "<td>$row[Name]</td>";
echo "<td>$row[num]</td>";
echo "</tr>";
echo "<tr><td>".htmlspecialchars(strip_tags($row["Name"]))."</td><td>".htmlspecialchars(strip_tags($row["num"]))."</td></tr>";
}
} else {
mysqli_close($connection);
Expand All @@ -48,11 +45,7 @@
$result = mysqli_query($connection, $query);
if (mysqli_num_rows($result) != 0) {
while ($row = mysqli_fetch_array($result)) {
echo "<tr>";
echo "<td>$row[Name]</td>";
echo "<td>$row[TimeStamp]</td>";
echo "<td>$row[serverName]</td>";
echo "</tr>";
echo "<tr><td>".htmlspecialchars(strip_tags($row["Name"]))."</td><td>".htmlspecialchars(strip_tags($row["TimeStamp"]))."</td><td>".htmlspecialchars(strip_tags($row["serverName"]))."</td></tr>";
}
} else {
mysqli_close($connection);
Expand Down

0 comments on commit fc46814

Please sign in to comment.