From 7dc5338e4d2a86fbbeea5718e87779dd94e11602 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Sat, 2 Jun 2018 21:51:31 -0600 Subject: [PATCH] Update devices.php --- app/devices/devices.php | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/app/devices/devices.php b/app/devices/devices.php index 8a4d17d3fd..93259b5f1d 100644 --- a/app/devices/devices.php +++ b/app/devices/devices.php @@ -204,7 +204,7 @@ if (permission_exists('device_export')) { echo " \n"; } - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo " \n"; @@ -249,7 +249,7 @@ echo "\n"; echo "\n"; - if (count($devices) > 0) { + if (is_array($devices)) { foreach($devices as $row) { $device_profile_name = ''; @@ -259,28 +259,28 @@ } } - $tr_link = (permission_exists('device_edit')) ? "href='device_edit.php?id=".$row['device_uuid']."'" : null; + $tr_link = (permission_exists('device_edit')) ? "href='device_edit.php?id=".escape($row['device_uuid'])."'" : null; echo "\n"; if ($_GET['show'] == "all" && permission_exists('device_all')) { - echo " ".$_SESSION['domains'][$row['domain_uuid']]['domain_name']."\n"; + echo " ".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])."\n"; } echo " \n"; - echo (permission_exists('device_edit')) ? "".format_mac($row['device_mac_address'])."" : format_mac($row['device_mac_address']); + echo (permission_exists('device_edit')) ? "".format_mac(escape($row['device_mac_address']))."" : format_mac(escape($row['device_mac_address'])); echo " \n"; - echo " ".$row['device_label']." \n"; + echo " ".escape($row['device_label'])." \n"; if ($device_alternate) { echo " \n"; if (strlen($row['device_uuid_alternate']) > 0) { - echo " ".$row['alternate_label']."\n"; + echo " ".escape($row['alternate_label'])."\n"; } echo " \n"; } - echo " ".$row['device_vendor']." \n"; - echo " ".$row['device_template']." \n"; - echo " ".$device_profile_name." \n"; - echo " ".$text['label-'.$row['device_enabled']]." \n"; - echo " ".$row['device_provisioned_date']." - ".$row['device_provisioned_method']." - ".$row['device_provisioned_ip']." \n"; - echo " ".$row['device_description']." \n"; + echo " ".escape($row['device_vendor'])." \n"; + echo " ".escape($row['device_template'])." \n"; + echo " ".escape($device_profile_name)." \n"; + echo " ".$text['label-'.escape($row['device_enabled'])]." \n"; + echo " ".escape($row['device_provisioned_date'])." - ".escape($row['device_provisioned_method'])." - ".escape($row['device_provisioned_ip'])." \n"; + echo " ".escape($row['device_description'])." \n"; echo " \n"; if (permission_exists('device_edit')) { echo "$v_link_label_edit\n";