|
51 | 51 | if ($data['action'] == 'cli') { |
52 | 52 | $width = 'wide'; |
53 | 53 | $output .= '<table style="width:100%" class="' . $width . '"><tr><td>'; |
54 | | - $output .= '<span><b>' . __('Page:', 'audit') . '</b> <i>' . $data['page'] . '</i></span>'; |
55 | | - $output .= '<br><span><b>' . __('User:', 'audit') . '</b> <i>' . $data['user_agent'] . '</i></span>'; |
56 | | - $output .= '<br><span><b>' . __('IP Address:', 'audit') . '</b> <i>' . $data['ip_address'] . '</i></span>'; |
57 | | - $output .= '<br><span><b>' . __('Date:', 'audit') . '</b> <i>' . $data['event_time'] . '</i></span>'; |
58 | | - $output .= '<br><span><b>' . __('Action:', 'audit') . '</b> <i>' . $data['action'] . '</i></span>'; |
| 54 | + $output .= '<span><b>' . __('Page:', 'audit') . '</b> <i>' . html_escape($data['page']) . '</i></span>'; |
| 55 | + $output .= '<br><span><b>' . __('User:', 'audit') . '</b> <i>' . html_escape($data['user_agent']) . '</i></span>'; |
| 56 | + $output .= '<br><span><b>' . __('IP Address:', 'audit') . '</b> <i>' . html_escape($data['ip_address']) . '</i></span>'; |
| 57 | + $output .= '<br><span><b>' . __('Date:', 'audit') . '</b> <i>' . html_escape($data['event_time']) . '</i></span>'; |
| 58 | + $output .= '<br><span><b>' . __('Action:', 'audit') . '</b> <i>' . html_escape($data['action']) . '</i></span>'; |
59 | 59 | $output .= '<hr>'; |
60 | | - $output .= '<span><b>' . __('Script:', 'audit') . '</b> <i>' . $data['post'] . '</i></span>'; |
| 60 | + $output .= '<span><b>' . __('Script:', 'audit') . '</b> <i>' . html_escape($data['post']) . '</i></span>'; |
61 | 61 | } elseif (cacti_sizeof($data)) { |
62 | 62 | $attribs = json_decode($data['post']); |
63 | 63 |
|
|
74 | 74 | } |
75 | 75 |
|
76 | 76 | $output .= '<table style="width:100%" class="' . $width . '"><tr><td>'; |
77 | | - $output .= '<span><b>' . __('Page:', 'audit') . '</b> <i>' . $data['page'] . '</i></span>'; |
78 | | - $output .= '<br><span><b>' . __('User:', 'audit') . '</b> <i>' . get_username($data['user_id']) . '</i></span>'; |
79 | | - $output .= '<br><span><b>' . __('IP Address:', 'audit') . '</b> <i>' . $data['ip_address'] . '</i></span>'; |
80 | | - $output .= '<br><span><b>' . __('Date:', 'audit') . '</b> <i>' . $data['event_time'] . '</i></span>'; |
81 | | - $output .= '<br><span><b>' . __('Action:', 'audit') . '</b> <i>' . $data['action'] . '</i></span>'; |
| 77 | + $output .= '<span><b>' . __('Page:', 'audit') . '</b> <i>' . html_escape($data['page']) . '</i></span>'; |
| 78 | + $output .= '<br><span><b>' . __('User:', 'audit') . '</b> <i>' . html_escape(get_username($data['user_id'])) . '</i></span>'; |
| 79 | + $output .= '<br><span><b>' . __('IP Address:', 'audit') . '</b> <i>' . html_escape($data['ip_address']) . '</i></span>'; |
| 80 | + $output .= '<br><span><b>' . __('Date:', 'audit') . '</b> <i>' . html_escape($data['event_time']) . '</i></span>'; |
| 81 | + $output .= '<br><span><b>' . __('Action:', 'audit') . '</b> <i>' . html_escape($data['action']) . '</i></span>'; |
82 | 82 | $output .= '<hr>'; |
83 | 83 | $output .= '<table style="width:100%">'; |
84 | 84 |
|
|
0 commit comments