提交 9648880a 编写于 作者: huangxuan258's avatar huangxuan258

修改responsive_lovestu模板,去掉viewquestionanswer.php文件中可能对问题详情页面造成xss攻击得代码

上级 9efe5189
......@@ -79,7 +79,7 @@
</div>
<div class="detail-body photos">
{template question_content_header}
{eval echo clearlinkref(htmlspecialchars_decode($question['description']));}
{eval echo $question['description'];}
{template question_content_footer}
</div>
</div>
......@@ -128,7 +128,7 @@
</div>
<div class="detail-body jieda-body photos">
<p> {eval echo clearlinkref(htmlspecialchars_decode(replacewords($useranswer['content']))); }</p>
<p> {eval echo replacewords($useranswer['content']); }</p>
<div class="appendcontent">
<!--{loop $useranswer['appends'] $append}-->
<div class="appendbox">
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册