From 07d951c577e4828a138f8ab58ef0833db3cc19b9 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Fri, 29 Jun 2018 22:58:48 -0600 Subject: [PATCH] Update extensions.php --- app/extensions/extensions.php | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/app/extensions/extensions.php b/app/extensions/extensions.php index 7e5b3deffb..acf45397ea 100644 --- a/app/extensions/extensions.php +++ b/app/extensions/extensions.php @@ -17,7 +17,7 @@ The Initial Developer of the Original Code is Mark J Crane - Portions created by the Initial Developer are Copyright (C) 2008-2017 + Portions created by the Initial Developer are Copyright (C) 2008-2018 the Initial Developer. All Rights Reserved. Contributor(s): @@ -103,7 +103,7 @@ //prepare to page the results $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 50; - $param = "&search=".$search; + $param = "&search=".escape($search); if (!isset($_GET['page'])) { $_GET['page'] = 0; } $_GET['page'] = check_str($_GET['page']); list($paging_controls_mini, $rows_per_page, $var_3) = paging($total_extensions, $param, $rows_per_page, true); //top @@ -216,11 +216,11 @@ if (is_array($extensions)) { foreach($extensions as $row) { - $tr_link = (permission_exists('extension_edit')) ? " href='extension_edit.php?id=".$row['extension_uuid']."'" : null; + $tr_link = (permission_exists('extension_edit')) ? " href='extension_edit.php?id=".escape($row['extension_uuid'])."'" : null; echo "\n"; if (permission_exists('extension_delete')) { echo " "; - echo " "; + echo " "; echo " "; $ext_ids[] = 'checkbox_'.$row['extension_uuid']; } @@ -229,7 +229,7 @@ } echo " "; if (permission_exists('extension_edit')) { - echo "".escape($row['extension']).""; + echo "".escape($row['extension']).""; } else { echo escape($row['extension']); @@ -247,13 +247,13 @@ $extension_number_alias .= '@'.$_SESSION['domain_name']; } $found_count = 0; - foreach ($registrations as $arr) { - if( - ($extension_number == $arr['user']) || + foreach ($registrations as $array) { + if ( + ($extension_number == $array['user']) || ($extension_number_alias != '' && - $extension_number_alias == $arr['user'] + $extension_number_alias == $array['user'] ) - ){ + ) { $found_count++; } } @@ -262,7 +262,7 @@ } else { echo "No"; } - unset($extension_number, $extension_number_alias, $found_count, $arr); + unset($extension_number, $extension_number_alias, $found_count, $array); echo " \n"; } @@ -271,10 +271,10 @@ echo " "; if (permission_exists('extension_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('extension_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo "\n"; echo "\n";