aboutsummaryrefslogtreecommitdiffstats
path: root/config/spamd/spamd_db.php
diff options
context:
space:
mode:
authorjim-p <jimp@pfsense.org>2014-02-18 16:15:54 -0500
committerjim-p <jimp@pfsense.org>2014-02-18 16:15:54 -0500
commita973e73b6fe151a342d5c998ed02c3fce482d006 (patch)
tree3db0645d2834c5124db6f2dd66d97a5005ca4702 /config/spamd/spamd_db.php
parent48a6f785e551967611ca49f40c05d1a567dd628e (diff)
downloadpfsense-packages-a973e73b6fe151a342d5c998ed02c3fce482d006.tar.gz
pfsense-packages-a973e73b6fe151a342d5c998ed02c3fce482d006.tar.bz2
pfsense-packages-a973e73b6fe151a342d5c998ed02c3fce482d006.zip
Use escapeshellarg for spamd; remove unused echo.
Diffstat (limited to 'config/spamd/spamd_db.php')
-rw-r--r--config/spamd/spamd_db.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/config/spamd/spamd_db.php b/config/spamd/spamd_db.php
index 112fdd71..c4c8ffe2 100644
--- a/config/spamd/spamd_db.php
+++ b/config/spamd/spamd_db.php
@@ -103,7 +103,7 @@ if($_POST['spamtrapemail'] <> "") {
}
if($_GET['getstatus'] <> "") {
- $status = exec("/usr/local/sbin/spamdb | grep \"{$_GET['getstatus']}\"");
+ $status = exec("/usr/local/sbin/spamdb | grep " . escapeshellarg($_GET['getstatus']));
if(stristr($status, "WHITE") == true) {
echo "WHITE";
} else if(stristr($status, "TRAPPED") == true) {