wrap pretty much all freemarker variables (i.e the data) in encodeHTML(data..). this...
[mir.git] / templates-dist / admin / head_nonavi.template
1  <a name="top">
2 <table width="100%" cellspacing="0" cellpadding="0">
3 <tr bgcolor="#006600"><td><img src="${encodeHTML(config.docRoot)}/img/head_small.gif" border="0" align="middle">&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" size="-1" color="white">
4         <b>${lang("imc.name")}</b></font></td></tr>
5 <if login_user><tr><td align="right"><font face="Verdana, Arial, Helvetica, sans-serif" size="-1" color="#006600">
6         <b>${encodeHTML(login_user.login)}</b> ${lang("head.logged_in")} /
7         <a href="${encodeHTML(actionRoot)}?module=logout">${lang("head.logout")}</a></font>
8         </td></tr>
9 </if>
10 <tr><td><hr></td></tr>
11 </table>