diff --git a/app/sip_profiles/sip_profiles.php b/app/sip_profiles/sip_profiles.php
index fe880bab52..80aa5cdf5a 100644
--- a/app/sip_profiles/sip_profiles.php
+++ b/app/sip_profiles/sip_profiles.php
@@ -93,8 +93,12 @@
$prep_statement = $db->prepare(check_sql($sql));
$prep_statement->execute();
$sip_profiles = $prep_statement->fetchAll(PDO::FETCH_NAMED);
+ foreach ($sip_profiles as &$row) { $row = array_map("escape", $row); }
unset ($prep_statement, $sql);
+//escape the search
+ $search = escape($search);
+
//alternate the row style
$c = 0;
$row_style["0"] = "row_style0";
@@ -106,7 +110,7 @@
echo "
".$text['title-sip_profiles']." | \n";
echo " \n";
@@ -137,19 +141,19 @@
if (is_array($sip_profiles)) {
foreach($sip_profiles as $row) {
if (permission_exists('sip_profile_edit')) {
- $tr_link = "href='sip_profile_edit.php?id=".escape($row['sip_profile_uuid'])."'";
+ $tr_link = "href='sip_profile_edit.php?id=".$row['sip_profile_uuid']."'";
}
echo "\n";
- echo " | ".escape($row['sip_profile_name'])." | \n";
- echo " ".escape($row['sip_profile_hostname'])." | \n";
- echo " ".escape($row['sip_profile_enabled'])." | \n";
- echo " ".escape($row['sip_profile_description'])." | \n";
+ echo " ".$row['sip_profile_name']." | \n";
+ echo " ".$row['sip_profile_hostname']." | \n";
+ echo " ".$row['sip_profile_enabled']." | \n";
+ echo " ".$row['sip_profile_description']." | \n";
echo " ";
if (permission_exists('sip_profile_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('sip_profile_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";