From 97cae830491a21511bccc78401ae89163617407f Mon Sep 17 00:00:00 2001 From: bnu Date: Wed, 4 Feb 2015 13:52:42 +0900 Subject: [PATCH] =?UTF-8?q?fix=20#1230=20SECISSUE=20-=20`xeVirtualRequestU?= =?UTF-8?q?rl`=20parameter=EB=A5=BC=20=EC=9D=B4=EC=9A=A9=ED=95=9C=20XSS=20?= =?UTF-8?q?=EC=B7=A8=EC=95=BD=EC=A0=90=20-=20=EC=A0=9C=EB=B3=B4=20:=20?= =?UTF-8?q?=ED=95=9C=EA=B5=AD=EC=9D=B8=ED=84=B0=EB=84=B7=EC=A7=84=ED=9D=A5?= =?UTF-8?q?=EC=9B=90?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- classes/display/VirtualXMLDisplayHandler.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/classes/display/VirtualXMLDisplayHandler.php b/classes/display/VirtualXMLDisplayHandler.php index 08e0a6045..aa67ee21d 100644 --- a/classes/display/VirtualXMLDisplayHandler.php +++ b/classes/display/VirtualXMLDisplayHandler.php @@ -14,8 +14,8 @@ class VirtualXMLDisplayHandler $message = $oModule->getMessage(); $redirect_url = $oModule->get('redirect_url'); $request_uri = Context::get('xeRequestURI'); - $request_url = Context::get('xeVirtualRequestUrl'); - $output = new stdClass; + $request_url = Context::getRequestUri(); + $output = new stdClass(); if(substr_compare($request_url, '/', -1) !== 0) {