FSN#37512 PENTEST 4.6.3 Cross-site scripting
svn path=/Website/trunk/; revision=30390
This commit is contained in:
@@ -171,7 +171,7 @@ user.auth_required_or_abort(this_bestelopdr.canDeliver);
|
|||||||
oRs = Oracle.Execute(sql);
|
oRs = Oracle.Execute(sql);
|
||||||
count = 0;
|
count = 0;
|
||||||
|
|
||||||
BLOCK_START("besdelivery", L("lcl_bes_delvery_h_pref") + S("bes_bestelopdr_prefix") + ordernr_id + L("lcl_bes_delvery_h_suf"));
|
BLOCK_START("besdelivery", L("lcl_bes_delvery_h_pref") + S("bes_bestelopdr_prefix") + safe.html(ordernr_id) + L("lcl_bes_delvery_h_suf"));
|
||||||
ROFIELDTR("fld", L("lcl_bes_Supplier"), oRs("prs_bedrijf_naam").value);
|
ROFIELDTR("fld", L("lcl_bes_Supplier"), oRs("prs_bedrijf_naam").value);
|
||||||
RWTEXTAREATR("notsat",
|
RWTEXTAREATR("notsat",
|
||||||
"fldremark",
|
"fldremark",
|
||||||
|
|||||||
@@ -115,7 +115,7 @@ var kosten = oRs("kosten").value;
|
|||||||
<body class="modal" id="mod_cntsplit">
|
<body class="modal" id="mod_cntsplit">
|
||||||
<form name=u2 action=cnt_split.asp?submit=1&cnt_key=<%=cnt_key%> method="post">
|
<form name=u2 action=cnt_split.asp?submit=1&cnt_key=<%=cnt_key%> method="post">
|
||||||
<%
|
<%
|
||||||
BLOCK_START("cntSplit", L("lcl_cnt_newversion_make") + internr);
|
BLOCK_START("cntSplit", L("lcl_cnt_newversion_make") + safe.html(internr));
|
||||||
|
|
||||||
var defaultdatum = new Date; // vandaag
|
var defaultdatum = new Date; // vandaag
|
||||||
FCLTcalendar( "splitdate",
|
FCLTcalendar( "splitdate",
|
||||||
|
|||||||
@@ -124,7 +124,7 @@ var maxlen = oRs(0).Value;
|
|||||||
<body class="modal" id="localebody">
|
<body class="modal" id="localebody">
|
||||||
<form id="lclform" name="lclform" action="fac_locale_data.asp?submit=1&kolomnaam=<%=kolomnaam%>&kolomkeyval=<%=kolomkeyval%>" method="post">
|
<form id="lclform" name="lclform" action="fac_locale_data.asp?submit=1&kolomnaam=<%=kolomnaam%>&kolomkeyval=<%=kolomkeyval%>" method="post">
|
||||||
<%
|
<%
|
||||||
BLOCK_START("mldReject", lbl);
|
BLOCK_START("mldReject", safe.html(lbl));
|
||||||
|
|
||||||
//kolomkeydata
|
//kolomkeydata
|
||||||
var talen_arr = [];
|
var talen_arr = [];
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ var autfunction = "WEB_PRSSYS";
|
|||||||
var authparams = user.checkAutorisation(autfunction);
|
var authparams = user.checkAutorisation(autfunction);
|
||||||
|
|
||||||
var submitting = getQParamInt("submit", 0) == 1;
|
var submitting = getQParamInt("submit", 0) == 1;
|
||||||
var lang = getQParam("lang", "NL"); // TODO: popup als niet meegegeven
|
var lang = getQParamSafe("lang", "NL"); // TODO: popup als niet meegegeven
|
||||||
var dialect_key = getQParamInt("dialect_key");
|
var dialect_key = getQParamInt("dialect_key");
|
||||||
var dialect_id = getQParam("dialect_id");
|
var dialect_id = getQParam("dialect_id");
|
||||||
|
|
||||||
|
|||||||
@@ -177,13 +177,13 @@ oRs.Close();
|
|||||||
$(document).ready(function () {
|
$(document).ready(function () {
|
||||||
FcltMgr.setTitle("<%=itsme ? L("lcl_prs_person_mijndata") : safe.jsstring(thisUser.naam())%>");
|
FcltMgr.setTitle("<%=itsme ? L("lcl_prs_person_mijndata") : safe.jsstring(thisUser.naam())%>");
|
||||||
});
|
});
|
||||||
|
|
||||||
function edit_photo(img)
|
function edit_photo(img)
|
||||||
{
|
{
|
||||||
var url = "<%=protectQS.create("../../appl/shared/BijlagenForm.asp?module=SML&key="+prs_key)%>";
|
var url = "<%=protectQS.create("../../appl/shared/BijlagenForm.asp?module=SML&key="+prs_key)%>";
|
||||||
FcltMgr.openModalDetail(url, L("lcl_prs_upload_foto"),
|
FcltMgr.openModalDetail(url, L("lcl_prs_upload_foto"),
|
||||||
{ callback: FcltMgr.reload } );
|
{ callback: FcltMgr.reload } );
|
||||||
}
|
}
|
||||||
</script>
|
</script>
|
||||||
<div id="show">
|
<div id="show">
|
||||||
<% if (prs_deleted == 1)
|
<% if (prs_deleted == 1)
|
||||||
@@ -330,7 +330,7 @@ oRs.Close();
|
|||||||
var oRs = Oracle.Execute (sql);
|
var oRs = Oracle.Execute (sql);
|
||||||
while (!oRs.eof)
|
while (!oRs.eof)
|
||||||
{
|
{
|
||||||
BLOCK_START("prsSubst", L("lcl_prs_substitutesblock") + ": " + oRs("fac_groep_omschrijving").Value);
|
BLOCK_START("prsSubst", L("lcl_prs_substitutesblock") + ": " + safe.html(oRs("fac_groep_omschrijving").Value));
|
||||||
var sql = "SELECT p.prs_perslid_key"
|
var sql = "SELECT p.prs_perslid_key"
|
||||||
+ ", " + S("prs_pers_string") + " prs_perslid_naam"
|
+ ", " + S("prs_pers_string") + " prs_perslid_naam"
|
||||||
+ " FROM fac_gebruikersgroep fgg"
|
+ " FROM fac_gebruikersgroep fgg"
|
||||||
|
|||||||
@@ -130,7 +130,7 @@ else
|
|||||||
<input type="hidden" id="nrRows" name="nrRows" value="0">
|
<input type="hidden" id="nrRows" name="nrRows" value="0">
|
||||||
<%
|
<%
|
||||||
if (ins_van_key_arr.length == 1)
|
if (ins_van_key_arr.length == 1)
|
||||||
BLOCK_START("ins_ruimteafdeling", safe.htmlattr(ins_srtname + " " + ins_name));
|
BLOCK_START("ins_ruimteafdeling", safe.html(ins_srtname + " " + ins_name));
|
||||||
else
|
else
|
||||||
BLOCK_START("ins_ruimteafdeling", L("lcl_alg_geselecteerde_ruimten") + ": " + ins_van_key_arr.length);
|
BLOCK_START("ins_ruimteafdeling", L("lcl_alg_geselecteerde_ruimten") + ": " + ins_van_key_arr.length);
|
||||||
|
|
||||||
|
|||||||
@@ -388,7 +388,7 @@ function parentButton()
|
|||||||
|
|
||||||
%></div><% // div.leftcontainer, de rest staat rechts
|
%></div><% // div.leftcontainer, de rest staat rechts
|
||||||
|
|
||||||
BLOCK_START("mldInfo", L("lcl_complain") + " "+ (mld_melding.prefix != null? mld_melding.prefix : "") + mld_key + (mld_melding.mld_onderwerp ? ": <span class='mldsubject'>" + mld_melding.mld_onderwerp + "</span>" : ""));
|
BLOCK_START("mldInfo", L("lcl_complain") + " "+ (mld_melding.prefix != null? mld_melding.prefix : "") + mld_key + (mld_melding.mld_onderwerp ? ": <span class='mldsubject'>" + safe.html(mld_melding.mld_onderwerp) + "</span>" : ""));
|
||||||
if (mld_melding.behandel_key) {
|
if (mld_melding.behandel_key) {
|
||||||
FCLTpersoonselector("sBehandel",
|
FCLTpersoonselector("sBehandel",
|
||||||
"sgBehandelaar",
|
"sgBehandelaar",
|
||||||
|
|||||||
@@ -284,7 +284,7 @@ else
|
|||||||
<input type="hidden" name="uitvkeystr" value="<%=uitv_key%>"/>
|
<input type="hidden" name="uitvkeystr" value="<%=uitv_key%>"/>
|
||||||
<input type="hidden" name="behandelaar" value="<%=mld_opdr.contactpers_key%>"/>
|
<input type="hidden" name="behandelaar" value="<%=mld_opdr.contactpers_key%>"/>
|
||||||
<%
|
<%
|
||||||
BLOCK_START({collapsed: true, title: mld_opdr.opdr_type_omschr});
|
BLOCK_START({collapsed: true, title: safe.html(mld_opdr.opdr_type_omschr)});
|
||||||
FCLTuitvoerendeselector("uitvoerende",
|
FCLTuitvoerendeselector("uitvoerende",
|
||||||
"sgUitv",
|
"sgUitv",
|
||||||
{ uitvoerendekey: mld_opdr.uitvoerende_key,
|
{ uitvoerendekey: mld_opdr.uitvoerende_key,
|
||||||
|
|||||||
@@ -411,7 +411,7 @@ else
|
|||||||
|
|
||||||
if (rsv_ruimte_key == -1)
|
if (rsv_ruimte_key == -1)
|
||||||
{ // Nieuw. Datum en tijd heb je al in vorige schermen gekozen
|
{ // Nieuw. Datum en tijd heb je al in vorige schermen gekozen
|
||||||
BLOCK_START({collapsed: true, title: rsv.activity});
|
BLOCK_START({collapsed: true, title: safe.html(rsv.activity) });
|
||||||
ROFIELD("fld", L("lcl_place") , rsv.ruimtenr.replace(/\n/,"<br>"));
|
ROFIELD("fld", L("lcl_place") , rsv.ruimtenr.replace(/\n/,"<br>"));
|
||||||
ROFIELD("fld", L("lcl_date"), toDateTimeString(rsv.ruimte_van) + "-" + toTimeString(rsv.ruimte_tot));
|
ROFIELD("fld", L("lcl_date"), toDateTimeString(rsv.ruimte_van) + "-" + toTimeString(rsv.ruimte_tot));
|
||||||
%>
|
%>
|
||||||
|
|||||||
Reference in New Issue
Block a user