From a2809552f2ac509d69afcb99ab26fbecf7b0b7ae Mon Sep 17 00:00:00 2001 From: Alexander Klimov Date: Wed, 23 Jul 2014 12:41:05 +0200 Subject: [PATCH] Do not use htmlspecialchars in view scripts fixes #6759 --- .../views/scripts/list/contacts.phtml | 8 ++++---- .../application/views/scripts/show/contact.phtml | 16 ++++++++-------- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/modules/monitoring/application/views/scripts/list/contacts.phtml b/modules/monitoring/application/views/scripts/list/contacts.phtml index 81a061973..9fc05de8e 100644 --- a/modules/monitoring/application/views/scripts/list/contacts.phtml +++ b/modules/monitoring/application/views/scripts/list/contacts.phtml @@ -26,23 +26,23 @@ $contactHelper = $this->getHelper('ContactFlags');
%2$s', t('Email'), - htmlspecialchars($contact->contact_email) + $this->escape($contact->contact_email) ) ?>
contact_pager): ?>
: - contact_pager) ?> + escape($contact->contact_pager) ?>
: - contact_notify_service_timeperiod) ?> + escape($contact->contact_notify_service_timeperiod) ?>
: - contact_notify_host_timeperiod) ?> + escape($contact->contact_notify_host_timeperiod) ?>
diff --git a/modules/monitoring/application/views/scripts/show/contact.phtml b/modules/monitoring/application/views/scripts/show/contact.phtml index 609bbbc69..a7b691eb4 100644 --- a/modules/monitoring/application/views/scripts/show/contact.phtml +++ b/modules/monitoring/application/views/scripts/show/contact.phtml @@ -7,8 +7,8 @@ $contactHelper = $this->getHelper('ContactFlags'); - contact_name) ?> (contact_alias) + escape($contact->contact_name) ?> (escape($contact->contact_alias) ?>) @@ -18,30 +18,30 @@ $contactHelper = $this->getHelper('ContactFlags'); %1$s', - htmlspecialchars($contact->contact_email) + $this->escape($contact->contact_email) ); ?> contact_pager): ?> - contact_pager) ?> + escape($contact->contact_pager) ?> - contactFlags($contact, 'service')) ?> + escape($contactHelper->contactFlags($contact, 'service')) ?> - contactFlags($contact, 'host')) ?> + escape($contactHelper->contactFlags($contact, 'host')) ?> - contact_notify_service_timeperiod) ?> + escape($contact->contact_notify_service_timeperiod) ?> - contact_notify_host_timeperiod) ?> + escape($contact->contact_notify_host_timeperiod) ?>