diff --git a/app/devices/device_edit.php b/app/devices/device_edit.php index d32361615a..20b3ba2a90 100644 --- a/app/devices/device_edit.php +++ b/app/devices/device_edit.php @@ -579,7 +579,7 @@ if ($_SERVER['HTTPS'] == 'on') { $_SERVER['HTTP_PROTOCOL'] = 'https'; } if ($_SERVER['SERVER_PORT'] == '443') { $_SERVER['HTTP_PROTOCOL'] = 'https'; } } - echo " window.location = '".$_SERVER['HTTP_PROTOCOL']."://".$domain_name.PROJECT_PATH."/app/provision/index.php?mac=".$device_mac_address."&file=' + d + '&content_type=application/octet-stream';\n"; + echo " window.location = '".$_SERVER['HTTP_PROTOCOL']."://".$domain_name.PROJECT_PATH."/app/provision/index.php?mac=".escape($device_mac_address)."&file=' + d + '&content_type=application/octet-stream';\n"; echo " }\n"; echo "\n"; @@ -705,7 +705,7 @@ if (permission_exists("device_line_password") && $device_template == "grandstream/wave") { echo " \n"; } - echo "  \n"; + echo "  \n"; if (permission_exists("device_files")) { //get the template directory $prov = new provision; @@ -731,7 +731,7 @@ } if (permission_exists('device_add') && $action != "add") { - echo " \n"; + echo " \n"; } echo " \n"; echo "\n"; @@ -751,15 +751,15 @@ echo "\n"; echo "\n"; if (permission_exists('device_mac_address')) { - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_mac_address']."\n"; } else { - echo $device_mac_address; + echo escape($device_mac_address); } echo " \n"; - echo " ".$device_provisioned_ip."(http|https)\n"; + echo " ".escape($device_provisioned_ip)."(http|https)\n"; echo "\n"; echo "\n"; @@ -769,12 +769,12 @@ echo "\n"; echo "\n"; if (permission_exists('device_label')) { - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_label']."\n"; } else { - echo $device_label; + echo escape($device_label); } echo "\n"; echo "\n"; @@ -885,7 +885,7 @@ } //add the primary key uuid if (strlen($row['device_line_uuid']) > 0) { - echo " \n"; + echo " \n"; } //show each row in the array echo " \n"; @@ -929,11 +929,11 @@ echo " \n"; if (permission_exists('device_line_server_address')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } else { - echo " \n"; + echo " \n"; } if (permission_exists('device_outbound_proxy_primary')) { @@ -941,39 +941,39 @@ $placeholder_label = $text['label-primary']; } echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; unset($placeholder_label); } if (permission_exists('device_outbound_proxy_secondary')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; if (permission_exists('device_line_auth_id')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } if (permission_exists('device_line_password')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; if (permission_exists('device_line_transport')) { @@ -987,25 +987,25 @@ echo " \n"; } else { - echo " \n"; + echo " \n"; } if (permission_exists('device_line_register_expires')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } else { - echo " \n"; + echo " \n"; } if (permission_exists('device_line_shared')) { echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; } else { - echo " \n"; + echo " \n"; } echo " \n"; @@ -1018,7 +1018,7 @@ echo " \n"; if (strlen($row['device_line_uuid']) > 0) { if (permission_exists('device_delete')) { - echo " $v_link_label_delete\n"; + echo " $v_link_label_delete\n"; } } echo " \n"; @@ -1121,7 +1121,7 @@ } //add the primary key uuid if (strlen($row['device_key_uuid']) > 0) { - echo " \n"; + echo " \n"; } //show all the rows in the array echo " \n"; @@ -1249,17 +1249,17 @@ echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; if (permission_exists('device_key_extension')) { echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; } echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; //echo " \n"; @@ -1268,7 +1268,7 @@ echo " \n"; if (strlen($row['device_key_uuid']) > 0) { if (permission_exists('device_key_delete')) { - echo " $v_link_label_delete\n"; + echo " $v_link_label_delete\n"; } } echo " \n"; @@ -1313,17 +1313,17 @@ } //add the primary key uuid if (strlen($row['device_setting_uuid']) > 0) { - echo " \n"; + echo " \n"; } //show alls rows in the array echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; echo "\n"; @@ -1345,7 +1345,7 @@ echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "\n"; if (strlen($text['description-settings']) > 0) { @@ -1356,10 +1356,10 @@ echo " \n"; if (strlen($row['device_setting_uuid']) > 0) { if (permission_exists('device_edit')) { - echo " $v_link_label_edit\n"; + echo " $v_link_label_edit\n"; } if (permission_exists('device_delete')) { - echo " $v_link_label_delete\n"; + echo " $v_link_label_delete\n"; } } echo " \n"; @@ -1399,8 +1399,8 @@ echo " ".$text['label-device']."\n"; echo "\n"; echo "\n"; - echo " \n"; - echo " \n"; + echo " \n"; + echo " \n"; echo " \n"; echo "
\n"; echo $text['description-device']."\n"; @@ -1415,7 +1415,7 @@ echo "\n"; echo "\n"; if (strlen($device_uuid_alternate) == 0) { - echo " "; + echo " "; } else { $label = $device_alternate[0]['device_label']; @@ -1423,7 +1423,7 @@ if (strlen($label) == 0) { $label = $device_alternate[0]['device_mac_address']; } echo " \n"; echo " \n"; - echo " "; + echo " "; echo " \n"; echo " \n"; echo "
$label $label $v_link_label_delete
\n"; @@ -1440,7 +1440,7 @@ echo " ".$text['label-device_vendor']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_vendor']."\n"; echo "\n"; @@ -1453,7 +1453,7 @@ echo " ".$text['label-device_model']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_model']."\n"; echo "\n"; @@ -1466,7 +1466,7 @@ echo " ".$text['label-device_firmware_version']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_firmware_version']."\n"; echo "\n"; @@ -1488,10 +1488,10 @@ } foreach ($_SESSION['domains'] as $row) { if ($row['domain_uuid'] == $domain_uuid) { - echo " \n"; + echo " \n"; } else { - echo " \n"; + echo " \n"; } } echo " \n"; @@ -1536,12 +1536,12 @@ echo "\n"; echo "\n"; if (permission_exists('device_description')) { - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-device_description']."\n"; } else { - echo $device_description."\n"; + echo escape($device_description)."\n"; } echo "\n"; @@ -1549,7 +1549,7 @@ echo " \n"; echo " \n"; if ($action == "update") { - echo " \n"; + echo " \n"; } echo "
"; echo " \n";