浏览代码

Protect the output of the config file against values containing quotes.

git-svn-id: http://svn.code.sf.net/p/itop/code/trunk@1133 a333f486-631f-4898-b8df-5754b55c2be0
dflaven 14 年之前
父节点
当前提交
1bb61cbbbf
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      core/config.class.inc.php

+ 1 - 1
core/config.class.inc.php

@@ -1016,7 +1016,7 @@ class Config
 						$sSeenAs = $aSettingInfo['value'] ? '1' : '0';
 						break;
 					default:
-						$sSeenAs = "'".$aSettingInfo['value']."'";
+						$sSeenAs = "'".addslashes($aSettingInfo['value'])."'";
 					}
 					fwrite($hFile, "\t'$sPropCode' => $sSeenAs,\n");
 				}