Skip to content

Commit e3ddbb6

Browse files
committed
Resolving Issue #94
Stored XSS in syslog_removal.php
1 parent cd594c6 commit e3ddbb6

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,7 @@ The sylog plugin has been in development for well over a decade with increasing
7979

8080
--- develop ---
8181
* issue#91: Page become blank after collecting multiple host syslog info
82+
* issue#94: Stored XSS in syslog_removal.php
8283

8384
--- 2.2 ---
8485
* feature: Allow for reprocess message per rule

syslog_removal.php

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -334,9 +334,9 @@ function api_syslog_removal_reprocess($id) {
334334
$syslog_removed = $syslog_items['removed'];
335335
$syslog_xferred = $syslog_items['xferred'];
336336

337-
$name = db_fetch_cell_prepared('SELECT name
338-
FROM syslog_remove
339-
WHERE id = ?',
337+
$name = db_fetch_cell_prepared('SELECT name
338+
FROM syslog_remove
339+
WHERE id = ?',
340340
array($id));
341341

342342
raise_message('syslog_info' . $id, __('Rule \'%s\' resulted in %s/%s messages removed/transferred', $name, $syslog_removed, $syslog_xferred, 'syslog'), MESSAGE_LEVEL_INFO);
@@ -703,7 +703,7 @@ function syslog_removal() {
703703
form_selectable_cell(filter_value(title_trim($removal['name'], read_config_option('max_title_length')), get_request_var('filter'), $config['url_path'] . 'plugins/syslog/syslog_removal.php?action=edit&id=' . $removal['id']), $removal['id']);
704704
form_selectable_cell((($removal['enabled'] == 'on') ? __('Yes', 'syslog'):__('No', 'syslog')), $removal['id']);
705705
form_selectable_cell($message_types[$removal['type']], $removal['id']);
706-
form_selectable_cell($removal['message'], $removal['id']);
706+
form_selectable_ecell($removal['message'], $removal['id']);
707707
form_selectable_cell((($removal['method'] == 'del') ? __('Deletion', 'syslog'): __('Transfer', 'syslog')), $removal['id']);
708708
form_selectable_cell(date('Y-m-d H:i:s', $removal['date']), $removal['id']);
709709
form_selectable_cell($removal['user'], $removal['id']);

0 commit comments

Comments
 (0)