|
6 | 6 | if ($installMode === 0) {
|
7 | 7 | $database_name = '';
|
8 | 8 | $database_server = 'localhost';
|
9 |
| - $table_prefix = base_convert(mt_rand(10, 20), 10, 36) . |
10 |
| - substr(str_shuffle('0123456789abcdefghijklmnopqrstuvwxyz'), mt_rand(0, 33), 3) . |
11 |
| - '_'; |
| 9 | + $table_prefix = base_convert(mt_rand(10, 20), 10, 36) . substr(str_shuffle('0123456789abcdefghijklmnopqrstuvwxyz'), mt_rand(0, 33), 3) . '_'; |
12 | 10 | } else {
|
13 | 11 | $database_name = '';
|
14 | 12 |
|
|
66 | 64 | $database_connection_method = 'SET CHARACTER SET';
|
67 | 65 | }
|
68 | 66 |
|
69 |
| -$ph['database_name'] = isset($_POST['database_name']) ? $_POST['database_name'] : $database_name; |
70 |
| -$ph['tableprefix'] = isset($_POST['tableprefix']) ? $_POST['tableprefix'] : $table_prefix; |
| 67 | +$ph['database_name'] = isset($_POST['database_name']) ? strip_tags($_POST['database_name']) : $database_name; |
| 68 | +$ph['tableprefix'] = isset($_POST['tableprefix']) ? strip_tags($_POST['tableprefix']) : $table_prefix; |
71 | 69 | $ph['selected_set_character_set'] = isset($database_connection_method) && $database_connection_method === 'SET CHARACTER SET' ? 'selected' : '';
|
72 | 70 | $ph['selected_set_names'] = isset($database_connection_method) && $database_connection_method === 'SET NAMES' ? 'selected' : '';
|
73 | 71 | $ph['show#connection_method'] = (($installMode == 0) || ($installMode == 2)) ? 'block' : 'none';
|
74 | 72 | $ph['database_collation'] = isset($_POST['database_collation']) ? $_POST['database_collation'] : $database_collation;
|
75 | 73 | $ph['show#AUH'] = ($installMode == 0) ? 'block' : 'none';
|
76 |
| -$ph['cmsadmin'] = isset($_POST['cmsadmin']) ? $_POST['cmsadmin'] : 'admin'; |
77 |
| -$ph['cmsadminemail'] = isset($_POST['cmsadminemail']) ? $_POST['cmsadminemail'] : ''; |
78 |
| -$ph['cmspassword'] = isset($_POST['cmspassword']) ? $_POST['cmspassword'] : ''; |
79 |
| -$ph['cmspasswordconfirm'] = isset($_POST['cmspasswordconfirm']) ? $_POST['cmspasswordconfirm'] : ''; |
| 74 | +$ph['cmsadmin'] = isset($_POST['cmsadmin']) ? strip_tags($_POST['cmsadmin']) : 'admin'; |
| 75 | +$ph['cmsadminemail'] = isset($_POST['cmsadminemail']) ? strip_tags($_POST['cmsadminemail']) : ''; |
| 76 | +$ph['cmspassword'] = isset($_POST['cmspassword']) ? strip_tags($_POST['cmspassword']) : ''; |
| 77 | +$ph['cmspasswordconfirm'] = isset($_POST['cmspasswordconfirm']) ? strip_tags($_POST['cmspasswordconfirm']) : ''; |
80 | 78 | $ph['managerLangs'] = getLangs($install_language);
|
81 | 79 | $ph['install_language'] = $install_language;
|
82 | 80 | $ph['installMode'] = $installMode;
|
|
0 commit comments