diff --git a/app/conference_centers/conference_session_details.php b/app/conference_centers/conference_session_details.php index 2935c20a91..a1d17c6895 100644 --- a/app/conference_centers/conference_session_details.php +++ b/app/conference_centers/conference_session_details.php @@ -22,16 +22,20 @@ Contributor(s): Mark J Crane */ -require_once "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (permission_exists('conference_session_view')) { - //access granted -} -else { - echo "access denied"; - exit; -} + +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('conference_session_view')) { + //access granted + } + else { + echo "access denied"; + exit; + } //add multi-lingual support $language = new text; @@ -187,20 +191,20 @@ else { $time_difference = $row['end_epoch'] - $row['start_epoch']; $time_difference = gmdate("G:i:s", $time_difference); } - $tr_link = (permission_exists('conference_session_details')) ? "href='/app/xml_cdr/xml_cdr_details.php?uuid=".$row['uuid']."'" : null; + $tr_link = (permission_exists('conference_session_details')) ? "href='/app/xml_cdr/xml_cdr_details.php?uuid=".escape($row['uuid'])."'" : null; echo "\n"; //echo " ".$row['meeting_uuid']." \n"; //echo " ".$row['conference_session_uuid']." \n"; - echo " ".$row['caller_id_name']." \n"; - echo " ".$row['caller_id_number']." \n"; - echo " ".ucwords($row['moderator'])." \n"; - echo " ".$row['network_addr']." \n"; + echo " ".escape($row['caller_id_name'])." \n"; + echo " ".escape($row['caller_id_number'])." \n"; + echo " ".ucwords(escape($row['moderator']))." \n"; + echo " ".escape($row['network_addr'])." \n"; echo " ".$time_difference." \n"; echo " ".$start_date." \n"; echo " ".$end_date." \n"; if (permission_exists('conference_session_details')) { echo " "; - echo " $v_link_label_view"; + echo " $v_link_label_view"; echo " \n"; } echo "\n"; @@ -228,4 +232,5 @@ else { //include the footer require_once "resources/footer.php"; -?> \ No newline at end of file + +?>