From 7dc36ea36faa36cafe11fae86c170ed031a17555 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Wed, 4 Jul 2018 11:02:15 -0600 Subject: [PATCH] Update sip_profiles.php --- app/sip_profiles/sip_profiles.php | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/app/sip_profiles/sip_profiles.php b/app/sip_profiles/sip_profiles.php index f1134e4f34..0adde199a2 100644 --- a/app/sip_profiles/sip_profiles.php +++ b/app/sip_profiles/sip_profiles.php @@ -92,7 +92,7 @@ $sql .= "limit $rows_per_page offset $offset "; $prep_statement = $db->prepare(check_sql($sql)); $prep_statement->execute(); - $result = $prep_statement->fetchAll(PDO::FETCH_NAMED); + $sip_profiles = $prep_statement->fetchAll(PDO::FETCH_NAMED); unset ($prep_statement, $sql); //alternate the row style @@ -106,7 +106,7 @@ echo " ".$text['title-sip_profiles']."\n"; echo "
\n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo "
\n"; @@ -134,28 +134,28 @@ echo "\n"; echo "\n"; - if (is_array($result)) { - foreach($result as $row) { + if (is_array($sip_profiles)) { + foreach($sip_profiles as $row) { if (permission_exists('sip_profile_edit')) { - $tr_link = "href='sip_profile_edit.php?id=".$row['sip_profile_uuid']."'"; + $tr_link = "href='sip_profile_edit.php?id=".escape($row['sip_profile_uuid'])."'"; } echo "\n"; - echo " ".$row['sip_profile_name']." \n"; - echo " ".$row['sip_profile_hostname']." \n"; - echo " ".$row['sip_profile_enabled']." \n"; - echo " ".$row['sip_profile_description']." \n"; + echo " ".escape($row['sip_profile_name'])." \n"; + echo " ".escape($row['sip_profile_hostname'])." \n"; + echo " ".escape($row['sip_profile_enabled'])." \n"; + echo " ".escape($row['sip_profile_description'])." \n"; echo " "; if (permission_exists('sip_profile_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('sip_profile_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n"; if ($c==0) { $c=1; } else { $c=0; } } //end foreach - unset($sql, $result, $row_count); + unset($sql, $sip_profiles); } //end if results echo "\n";