diff --git a/app/sip_profiles/sip_profiles.php b/app/sip_profiles/sip_profiles.php
index f1134e4f34..0adde199a2 100644
--- a/app/sip_profiles/sip_profiles.php
+++ b/app/sip_profiles/sip_profiles.php
@@ -92,7 +92,7 @@
$sql .= "limit $rows_per_page offset $offset ";
$prep_statement = $db->prepare(check_sql($sql));
$prep_statement->execute();
- $result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
+ $sip_profiles = $prep_statement->fetchAll(PDO::FETCH_NAMED);
unset ($prep_statement, $sql);
//alternate the row style
@@ -106,7 +106,7 @@
echo "
".$text['title-sip_profiles']." | \n";
echo " \n";
@@ -134,28 +134,28 @@
echo "\n";
echo "\n";
- if (is_array($result)) {
- foreach($result as $row) {
+ if (is_array($sip_profiles)) {
+ foreach($sip_profiles as $row) {
if (permission_exists('sip_profile_edit')) {
- $tr_link = "href='sip_profile_edit.php?id=".$row['sip_profile_uuid']."'";
+ $tr_link = "href='sip_profile_edit.php?id=".escape($row['sip_profile_uuid'])."'";
}
echo "
\n";
- echo " | ".$row['sip_profile_name']." | \n";
- echo " ".$row['sip_profile_hostname']." | \n";
- echo " ".$row['sip_profile_enabled']." | \n";
- echo " ".$row['sip_profile_description']." | \n";
+ echo " ".escape($row['sip_profile_name'])." | \n";
+ echo " ".escape($row['sip_profile_hostname'])." | \n";
+ echo " ".escape($row['sip_profile_enabled'])." | \n";
+ echo " ".escape($row['sip_profile_description'])." | \n";
echo " ";
if (permission_exists('sip_profile_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('sip_profile_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";
if ($c==0) { $c=1; } else { $c=0; }
} //end foreach
- unset($sql, $result, $row_count);
+ unset($sql, $sip_profiles);
} //end if results
echo "\n";