$msg= "<div align='center'>"
. sprintf(_("I tried to execute '%s', but it returned:"),
$sqspell_command) . "<pre>"
- . nl2br(join("\n", $sqspell_output)) . "</pre>"
+ . join("\n", htmlspecialchars($sqspell_output)) . "</pre>"
. "<form onsubmit=\"return false\">"
. "<input type=\"submit\" value=\" " . _("Close")
. " \" onclick=\"self.close()\"></form></div>";
* Local variables:
* mode: php
* End:
+ * vim: syntax=php
*/
?>
$msg .= "</td><td valign=\"top\">\n";
}
$msg .= "<input type=\"checkbox\" name=\"words_ary[]\" "
- . "value=\"$words_ary[$j]\"> $words_ary[$j]<br>";
+ . 'value="'.htmlspecialchars($words_ary[$j]). '"> '
+ . htmlspecialchars($words_ary[$j]) . "<br>\n";
}
$msg .= '</td></tr></table></td></tr>'
. "<tr bgcolor=\"$color[0]\" align=\"center\"><td>"
* Local variables:
* mode: php
* End:
+ * vim: syntax=php
*/
?>
* Remove word by word...
*/
$lang_words=str_replace("$words_ary[$i]\n", "", $lang_words);
- $msg .= "<li>$words_ary[$i]</li>\n";
+ $msg .= '<li>' . htmlspecialchars($words_ary[$i]) . "</li>\n";
}
$new_words_ary=split("\n", $lang_words);
/**
* Local variables:
* mode: php
* End:
+ * vim: syntax=php
*/
?>