aboutsummaryrefslogtreecommitdiffstats
path: root/config/openvpn-client-export/vpn_openvpn_export.php
diff options
context:
space:
mode:
authorjim-p <jimp@pfsense.org>2011-03-14 16:47:46 -0400
committerjim-p <jimp@pfsense.org>2011-03-14 16:48:52 -0400
commitfd982ebd4de3e10dc83fbb713ef1c6d7e2a23c82 (patch)
treeed7691ebbc95facf0af247cc3ac9922ee9f3aff6 /config/openvpn-client-export/vpn_openvpn_export.php
parent962c3f572905f3266b77b414eeb86880899ea03a (diff)
downloadpfsense-packages-fd982ebd4de3e10dc83fbb713ef1c6d7e2a23c82.tar.gz
pfsense-packages-fd982ebd4de3e10dc83fbb713ef1c6d7e2a23c82.tar.bz2
pfsense-packages-fd982ebd4de3e10dc83fbb713ef1c6d7e2a23c82.zip
Escape values so special characters don't fail (and also helps prevent shell command injection)
Diffstat (limited to 'config/openvpn-client-export/vpn_openvpn_export.php')
-rwxr-xr-xconfig/openvpn-client-export/vpn_openvpn_export.php22
1 files changed, 11 insertions, 11 deletions
diff --git a/config/openvpn-client-export/vpn_openvpn_export.php b/config/openvpn-client-export/vpn_openvpn_export.php
index 01a0507a..5c84ac80 100755
--- a/config/openvpn-client-export/vpn_openvpn_export.php
+++ b/config/openvpn-client-export/vpn_openvpn_export.php
@@ -425,22 +425,22 @@ function download_begin(act, i) {
var dlurl;
dlurl = "/vpn_openvpn_export.php?act=" + act;
- dlurl += "&srvid=" + servers[index][0];
+ dlurl += "&srvid=" + escape(servers[index][0]);
if (users[i]) {
- dlurl += "&usrid=" + users[i][0];
- dlurl += "&crtid=" + users[i][1];
+ dlurl += "&usrid=" + escape(users[i][0]);
+ dlurl += "&crtid=" + escape(users[i][1]);
}
- dlurl += "&useaddr=" + useaddr;
- dlurl += "&usetoken=" + usetoken;
+ dlurl += "&useaddr=" + escape(useaddr);
+ dlurl += "&usetoken=" + escape(usetoken);
if (usepass)
- dlurl += "&password=" + pass;
+ dlurl += "&password=" + escape(pass);
if (useproxy) {
- dlurl += "&proxy_addr=" + proxyaddr;
- dlurl += "&proxy_port=" + proxyport;
- dlurl += "&proxy_authtype=" + proxyauth;
+ dlurl += "&proxy_addr=" + escape(proxyaddr);
+ dlurl += "&proxy_port=" + escape(proxyport);
+ dlurl += "&proxy_authtype=" + escape(proxyauth);
if (useproxypass) {
- dlurl += "&proxy_user=" + proxyuser;
- dlurl += "&proxy_password=" + proxypass;
+ dlurl += "&proxy_user=" + escape(proxyuser);
+ dlurl += "&proxy_password=" + escape(proxypass);
}
}