diff --git a/app/fax/fax_files.php b/app/fax/fax_files.php index 348fc4050f..62d9c2f846 100644 --- a/app/fax/fax_files.php +++ b/app/fax/fax_files.php @@ -221,10 +221,10 @@ echo " \n"; echo " \n"; if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) { - echo " ".$text['header-inbox'].": ".$fax_name." (".$fax_extension.")\n"; + echo " ".$text['header-inbox'].": ".escape($fax_name)." (".escape($fax_extension).")\n"; } if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) { - echo " ".$text['header-sent'].": ".$fax_name." (".$fax_extension.")\n"; + echo " ".$text['header-sent'].": ".escape($fax_name)." (".escape($fax_extension).")\n"; } echo " \n"; echo " \n"; @@ -342,10 +342,10 @@ } echo " \n"; if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) { - echo " \n"; + echo " \n"; } if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) { - echo " \n"; + echo " \n"; } echo " $file_name"; echo " "; @@ -359,10 +359,10 @@ } if (file_exists($dir_fax.'/'.$file_name.".pdf")) { if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) { - echo " PDF\n"; + echo " PDF\n"; } if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) { - echo " PDF\n"; + echo " PDF\n"; } } else {