#18927846 : security patch

git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7500 201d5d3c-b55e-5fd7-737f-ddc643e51545
This commit is contained in:
haneul 2010-06-08 07:47:17 +00:00
parent 746b03b14a
commit 1c1b037786

View file

@ -83,7 +83,7 @@
// 메일 보내기
if($member_info->email_address) {
$url = 'mailto:'.$member_info->email_address;
$url = 'mailto:'.htmlspecialchars($member_info->email_address);
$icon_path = './modules/member/tpl/images/icon_sendmail.gif';
$oMemberController->addMemberPopupMenu($url,'cmd_send_email',$icon_path);
}
@ -91,11 +91,11 @@
// 홈페이지 보기
if($member_info->homepage)
$oMemberController->addMemberPopupMenu($member_info->homepage, 'homepage', './modules/member/tpl/images/icon_homepage.gif','blank');
$oMemberController->addMemberPopupMenu(htmlspecialchars($member_info->homepage), 'homepage', './modules/member/tpl/images/icon_homepage.gif','blank');
// 블로그 보기
if($member_info->blog)
$oMemberController->addMemberPopupMenu($member_info->blog, 'blog', './modules/member/tpl/images/icon_blog.gif','blank');
$oMemberController->addMemberPopupMenu(htmlspecialchars($member_info->blog), 'blog', './modules/member/tpl/images/icon_blog.gif','blank');
// trigger 호출 (after)
ModuleHandler::triggerCall('member.getMemberMenu', 'after', $null);