diff --git a/app/dialplans/dialplan_edit.php b/app/dialplans/dialplan_edit.php index 5e7437ec76..7afc3451be 100644 --- a/app/dialplans/dialplan_edit.php +++ b/app/dialplans/dialplan_edit.php @@ -206,7 +206,7 @@ else if ($action == "update") { messages::add($text['message-update']); } - header("Location: ?id=".$dialplan_uuid.(($app_uuid != '') ? "&app_uuid=".$app_uuid : null)); + header("Location: ?id=".escape($dialplan_uuid).(($app_uuid != '') ? "&app_uuid=".escape($app_uuid) : null)); exit; } //(count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) @@ -364,7 +364,7 @@ //show the content echo "
\n"; - echo "\n"; + echo "\n"; echo "\n"; echo " \n"; @@ -373,10 +373,10 @@ echo " \n"; echo " \n"; echo " \n"; @@ -399,7 +399,7 @@ echo " ".$text['label-name']."\n"; echo " \n"; echo " \n"; echo " \n"; @@ -408,7 +408,7 @@ echo " ".$text['label-number']."\n"; echo " \n"; echo " \n"; echo " \n"; @@ -499,10 +499,10 @@ } if (is_array($_SESSION['domains'])) foreach ($_SESSION['domains'] as $row) { if ($row['domain_uuid'] == $domain_uuid) { - echo " \n"; + echo " \n"; } else { - echo " \n"; + echo " \n"; } } echo " \n"; @@ -539,7 +539,7 @@ echo " ".$text['label-description']."\n"; echo " \n"; echo " \n"; echo " \n"; echo "
\n"; if (permission_exists('dialplan_xml')) { - echo " 0) ? "app_uuid=".$app_uuid : null)."';\" value='".$text['button-xml']."'>\n"; + echo " 0) ? "app_uuid=".escape($app_uuid) : null)."';\" value='".$text['button-xml']."'>\n"; } - echo " 0) ? "?app_uuid=".$app_uuid : null)."';\" value='".$text['button-back']."'>\n"; - echo " \n"; + echo " 0) ? "?app_uuid=".escape($app_uuid) : null)."';\" value='".$text['button-back']."'>\n"; + echo " \n"; echo " \n"; echo "
\n"; - echo " \n"; + echo " \n"; echo "
\n"; - echo " \n"; + echo " \n"; echo "
\n"; - echo " \n"; + echo " \n"; echo "
\n"; @@ -617,13 +617,13 @@ } //add the primary key uuid if (strlen($dialplan_detail_uuid) > 0) { - echo " \n"; + echo " \n"; } //tag $selected = "selected=\"selected\" "; echo "\n"; if ($element['hidden']) { - echo " \n"; + echo " \n"; } echo " \n"; if (strlen($dialplan_detail_type) > 0) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } else { @@ -678,11 +678,13 @@ //} //if (strlen($dialplan_detail_tag) == 0 || $dialplan_detail_tag == "action" || $dialplan_detail_tag == "anti-action") { echo " \n"; - if (is_array($_SESSION['switch']['applications'])) foreach ($_SESSION['switch']['applications'] as $row) { - if (strlen($row) > 0) { - $application = explode(",", $row); - if ($application[0] != "name" && stristr($application[0], "[") != true) { - echo " \n"; + if (is_array($_SESSION['switch']['applications'])) { + foreach ($_SESSION['switch']['applications'] as $row) { + if (strlen($row) > 0) { + $application = explode(",", $row); + if ($application[0] != "name" && stristr($application[0], "[") != true) { + echo " \n"; + } } } } @@ -711,14 +713,14 @@ unset ($prep_statement, $sql, $bridge_statement); } } - echo " \n"; + echo " \n"; } - echo " \n"; + echo " \n"; echo "\n"; //break echo "\n"; if ($element['hidden']) { - echo " \n"; + echo " \n"; } echo " \n"; echo " \n"; @@ -744,12 +746,12 @@ if ($element['hidden']) { echo " \n"; } - echo " \n"; + echo " \n"; /* echo " \n"; + echo " \n"; /* echo "