Bug 3652: Fixes XSS vulnerabilities and XTHML errors in opac-search-history.tmpl
authorGarry Collum <gcollum@gmail.com>
Tue, 16 Feb 2010 00:17:01 +0000 (19:17 -0500)
committerGalen Charlton <gmcharlt@gmail.com>
Tue, 16 Feb 2010 11:42:44 +0000 (06:42 -0500)
Signed-off-by: Galen Charlton <gmcharlt@gmail.com>
koha-tmpl/opac-tmpl/prog/en/modules/opac-search-history.tmpl

index 657ad14..f129925 100644 (file)
@@ -46,7 +46,7 @@
                    <!-- TMPL_LOOP NAME="recentSearches" -->
                    <tr>
                        <td><!-- TMPL_VAR NAME="time" --></td>
-                       <td><a href="/cgi-bin/koha/opac-search.pl?<!-- TMPL_VAR NAME="query_cgi"  -->"><!-- TMPL_VAR NAME="query_desc" ESCAPE="html" --></a></td>
+                       <td><a href="/cgi-bin/koha/opac-search.pl?<!-- TMPL_VAR NAME="query_cgi" ESCAPE="html" -->"><!-- TMPL_VAR NAME="query_desc" ESCAPE="html" --></a></td>
                        <td><!-- TMPL_VAR NAME="total" --></td>
                    </tr>
                    <!-- /TMPL_LOOP -->
@@ -64,7 +64,7 @@
                    <!-- TMPL_LOOP NAME="previousSearches" -->
                    <tr>
                        <td><!-- TMPL_VAR NAME="time" --></td>
-                       <td><a href="/cgi-bin/koha/opac-search.pl?<!-- TMPL_VAR NAME="query_cgi"  -->"><!-- TMPL_VAR NAME="query_desc" --></a></td>
+                       <td><a href="/cgi-bin/koha/opac-search.pl?<!-- TMPL_VAR NAME="query_cgi" ESCAPE="html" -->"><!-- TMPL_VAR NAME="query_desc" ESCAPE="html" --></a></td>
                        <td><!-- TMPL_VAR NAME="total" --></td>
                    </tr>
                    <!-- /TMPL_LOOP -->