aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorErmal Luçi <eri@pfsense.org>2010-02-26 16:04:05 +0000
committerErmal Luçi <eri@pfsense.org>2010-02-26 16:04:34 +0000
commit8d98e14a7f6ec1dc0a62fa50c2cb5bb5e20afb1a (patch)
treec657c65e3f9f2a119e4abb6f959a22cc4a2dae94
parent62eadf9df48d2bf3e21e0634d8b35efc70ee0244 (diff)
downloadpfsense-packages-8d98e14a7f6ec1dc0a62fa50c2cb5bb5e20afb1a.tar.gz
pfsense-packages-8d98e14a7f6ec1dc0a62fa50c2cb5bb5e20afb1a.tar.bz2
pfsense-packages-8d98e14a7f6ec1dc0a62fa50c2cb5bb5e20afb1a.zip
Ticket #383. Escape special javascript characters. It would be wiser to prevent them from being used on certificate names.
-rwxr-xr-xconfig/openvpn-client-export/vpn_openvpn_export.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/config/openvpn-client-export/vpn_openvpn_export.php b/config/openvpn-client-export/vpn_openvpn_export.php
index 2af4da59..95637c26 100755
--- a/config/openvpn-client-export/vpn_openvpn_export.php
+++ b/config/openvpn-client-export/vpn_openvpn_export.php
@@ -306,7 +306,7 @@ servers[<?=$sindex;?>][1][<?=$uindex;?>] = new Array();
servers[<?=$sindex;?>][1][<?=$uindex;?>][0] = '<?=$user['uindex'];?>';
servers[<?=$sindex;?>][1][<?=$uindex;?>][1] = '<?=$user['cindex'];?>';
servers[<?=$sindex;?>][1][<?=$uindex;?>][2] = '<?=$user['name'];?>';
-servers[<?=$sindex;?>][1][<?=$uindex;?>][3] = '<?=$user['certname'];?>';
+servers[<?=$sindex;?>][1][<?=$uindex;?>][3] = '<?=str_replace("'", "\\'", $user['certname']);?>';
<? endforeach; ?>
<? endforeach; ?>