From 6f323ff54643622bcd31f6b7577ab1a23d16f590 Mon Sep 17 00:00:00 2001 From: Byron Jones Date: Wed, 28 Dec 2011 17:03:56 -0500 Subject: Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular and graphical reports in debug mode r=gerv, a=LpSolit --- report.cgi | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'report.cgi') diff --git a/report.cgi b/report.cgi index a71776bfe..dccc470a7 100755 --- a/report.cgi +++ b/report.cgi @@ -288,9 +288,9 @@ print $cgi->header(-type => $format->{'ctype'}, if ($cgi->param('debug')) { require Data::Dumper; print "
data hash:\n";
-    print Data::Dumper::Dumper(%data) . "\n\n";
+    print html_quote(Data::Dumper::Dumper(%data)) . "\n\n";
     print "data array:\n";
-    print Data::Dumper::Dumper(@image_data) . "\n\n
"; + print html_quote(Data::Dumper::Dumper(@image_data)) . "\n\n"; } # All formats point to the same section of the documentation. -- cgit v1.2.3-24-g4f1b