XSS Defense, 1.5.2.6 version up

git-svn-id: http://xe-core.googlecode.com/svn/trunk@10796 201d5d3c-b55e-5fd7-737f-ddc643e51545
This commit is contained in:
ovclas 2012-06-26 01:27:56 +00:00
parent ea84468e7d
commit abfcd484bf
2 changed files with 2 additions and 2 deletions

View file

@ -13,7 +13,7 @@
* @brief display XE's full version
* Even The file should be revised when releasing altough no change is made
**/
define('__XE_VERSION__', '1.5.2.5');
define('__XE_VERSION__', '1.5.2.6');
define('__ZBXE_VERSION__', __XE_VERSION__); // deprecated : __ZBXE_VERSION__ will be removed. Use __XE_VERSION__ instead.
/**

View file

@ -686,7 +686,7 @@
**/
function removeHackTag($content) {
// change the specific tags to the common texts
$content = preg_replace('@<(\/?(?:html|body|head|title|meta|base|link|script|style|applet|iframe)[\s>])@i', '&lt;$1', $content);
$content = preg_replace('@<(\/?(?:html|body|head|title|meta|base|link|script|style|applet|iframe)(/*)[\w\s>])@i', '&lt;$1', $content);
/**
* Remove codes to abuse the admin session in src by tags of imaages and video postings