diff --git a/app/fax/fax_files.php b/app/fax/fax_files.php
index 348fc4050f..62d9c2f846 100644
--- a/app/fax/fax_files.php
+++ b/app/fax/fax_files.php
@@ -221,10 +221,10 @@
echo "
\n";
echo " | \n";
if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) {
- echo " ".$text['header-inbox'].": ".$fax_name." (".$fax_extension.")\n";
+ echo " ".$text['header-inbox'].": ".escape($fax_name)." (".escape($fax_extension).")\n";
}
if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) {
- echo " ".$text['header-sent'].": ".$fax_name." (".$fax_extension.")\n";
+ echo " ".$text['header-sent'].": ".escape($fax_name)." (".escape($fax_extension).")\n";
}
echo " | \n";
echo " \n";
@@ -342,10 +342,10 @@
}
echo " | \n";
if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) {
- echo " \n";
+ echo " \n";
}
if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) {
- echo " \n";
+ echo " \n";
}
echo " $file_name";
echo " ";
@@ -359,10 +359,10 @@
}
if (file_exists($dir_fax.'/'.$file_name.".pdf")) {
if ($_REQUEST['box'] == 'inbox' && permission_exists('fax_inbox_view')) {
- echo " PDF\n";
+ echo " PDF\n";
}
if ($_REQUEST['box'] == 'sent' && permission_exists('fax_sent_view')) {
- echo " PDF\n";
+ echo " PDF\n";
}
}
else {
|