fixed missing escaping of textarea data
authorzapata <zapata>
Mon, 17 Mar 2003 21:04:12 +0000 (21:04 +0000)
committerzapata <zapata>
Mon, 17 Mar 2003 21:04:12 +0000 (21:04 +0000)
templates/admin/fileedit.template

index 601c83d..75f57a9 100755 (executable)
@@ -21,7 +21,7 @@
         <input type="hidden" name="do" value="update">
 
 
-        <textarea cols="120" rows="40" name="text" wrap=virtual>${text}</textarea>
+        <textarea cols="120" rows="40" name="text" wrap=virtual>${utility.encodeHTML(text)}</textarea>
 
 <br>