diff --git a/pandora_console/ChangeLog b/pandora_console/ChangeLog index 27a3859d68..4d3cff95ca 100644 --- a/pandora_console/ChangeLog +++ b/pandora_console/ChangeLog @@ -1,3 +1,8 @@ +2011-06-07 Javier Lanz + + * operation/events/events_list.php: Added rawurlencode and io_safe_input + where they were necessary + 2011-06-07 Junichi Satoh * operation/agentes/datos_agente.php: Improved filter. It allows diff --git a/pandora_console/operation/events/events_list.php b/pandora_console/operation/events/events_list.php index 8112a2d71d..7d4f53730d 100644 --- a/pandora_console/operation/events/events_list.php +++ b/pandora_console/operation/events/events_list.php @@ -98,7 +98,7 @@ switch($status) { } if ($search != "") { - $sql_post .= " AND evento LIKE '%".base64_decode($search)."%'"; + $sql_post .= " AND evento LIKE '%".io_safe_input($search)."%'"; } if ($event_type != "") { @@ -132,7 +132,7 @@ if ($event_view_hr > 0) { } $url = "index.php?sec=eventos&sec2=operation/events/events&search=" . - $search . "&event_type=" . $event_type . + rawurlencode($search) . "&event_type=" . $event_type . "&severity=" . $severity . "&status=" . $status . "&ev_group=" . $ev_group . "&refr=" . $config["refr"] . "&id_agent=" . $id_agent . "&id_event=" . $id_event . "&pagination=" . @@ -407,7 +407,7 @@ foreach ($result as $event) { // Event description $data[1] = ''; - $data[1] .= ''; + $data[1] .= ''; if (strlen ($event["evento"]) > 50) { $data[1] .= mb_substr (io_safe_output($event["evento"]), 0, 50)."..."; }