xss defense

git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.0@10219 201d5d3c-b55e-5fd7-737f-ddc643e51545
This commit is contained in:
ovclas 2012-02-27 10:15:28 +00:00
parent 5e7b21593f
commit ef6fa6a474

View file

@ -512,6 +512,9 @@
$args->member_srl = $member_srl;
$args->sid = md5(rand(rand(1111111,4444444),rand(4444445,9999999)));
$security = new Security($args->source_filename);
$args->source_filename = $security->encodeHTML();
$output = executeQuery('file.insertFile', $args);
if(!$output->toBool()) return $output;
// Call a trigger (after)