diff --git a/app/devices/device_edit.php b/app/devices/device_edit.php
index d32361615a..20b3ba2a90 100644
--- a/app/devices/device_edit.php
+++ b/app/devices/device_edit.php
@@ -579,7 +579,7 @@
if ($_SERVER['HTTPS'] == 'on') { $_SERVER['HTTP_PROTOCOL'] = 'https'; }
if ($_SERVER['SERVER_PORT'] == '443') { $_SERVER['HTTP_PROTOCOL'] = 'https'; }
}
- echo " window.location = '".$_SERVER['HTTP_PROTOCOL']."://".$domain_name.PROJECT_PATH."/app/provision/index.php?mac=".$device_mac_address."&file=' + d + '&content_type=application/octet-stream';\n";
+ echo " window.location = '".$_SERVER['HTTP_PROTOCOL']."://".$domain_name.PROJECT_PATH."/app/provision/index.php?mac=".escape($device_mac_address)."&file=' + d + '&content_type=application/octet-stream';\n";
echo " }\n";
echo "\n";
@@ -705,7 +705,7 @@
if (permission_exists("device_line_password") && $device_template == "grandstream/wave") {
echo " \n";
}
- echo " \n";
+ echo " \n";
if (permission_exists("device_files")) {
//get the template directory
$prov = new provision;
@@ -731,7 +731,7 @@
}
if (permission_exists('device_add') && $action != "add") {
- echo " \n";
+ echo " \n";
}
echo " \n";
echo "\n";
@@ -751,15 +751,15 @@
echo "\n";
echo "
\n";
if (permission_exists('device_mac_address')) {
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_mac_address']."\n";
}
else {
- echo $device_mac_address;
+ echo escape($device_mac_address);
}
echo " \n";
- echo " ".$device_provisioned_ip."(http|https)\n";
+ echo " ".escape($device_provisioned_ip)."(http|https)\n";
echo " | \n";
echo "\n";
@@ -769,12 +769,12 @@
echo "\n";
echo "\n";
if (permission_exists('device_label')) {
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_label']."\n";
}
else {
- echo $device_label;
+ echo escape($device_label);
}
echo " | \n";
echo "\n";
@@ -885,7 +885,7 @@
}
//add the primary key uuid
if (strlen($row['device_line_uuid']) > 0) {
- echo " \n";
+ echo " \n";
}
//show each row in the array
echo " \n";
@@ -929,11 +929,11 @@
echo " \n";
if (permission_exists('device_line_server_address')) {
echo " | \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
else {
- echo " \n";
+ echo " \n";
}
if (permission_exists('device_outbound_proxy_primary')) {
@@ -941,39 +941,39 @@
$placeholder_label = $text['label-primary'];
}
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
unset($placeholder_label);
}
if (permission_exists('device_outbound_proxy_secondary')) {
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
if (permission_exists('device_line_auth_id')) {
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
if (permission_exists('device_line_password')) {
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
if (permission_exists('device_line_transport')) {
@@ -987,25 +987,25 @@
echo " \n";
}
else {
- echo " \n";
+ echo " \n";
}
if (permission_exists('device_line_register_expires')) {
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
else {
- echo " \n";
+ echo " \n";
}
if (permission_exists('device_line_shared')) {
echo " \n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
else {
- echo " \n";
+ echo " \n";
}
echo " \n";
@@ -1018,7 +1018,7 @@
echo " | \n";
if (strlen($row['device_line_uuid']) > 0) {
if (permission_exists('device_delete')) {
- echo " $v_link_label_delete\n";
+ echo " $v_link_label_delete\n";
}
}
echo " | \n";
@@ -1121,7 +1121,7 @@
}
//add the primary key uuid
if (strlen($row['device_key_uuid']) > 0) {
- echo " \n";
+ echo " \n";
}
//show all the rows in the array
echo "
\n";
@@ -1249,17 +1249,17 @@
echo "\n";
echo "| \n";
- echo " \n";
+ echo " \n";
echo " | \n";
if (permission_exists('device_key_extension')) {
echo "\n";
- echo " \n";
+ echo " \n";
echo " | \n";
}
echo "\n";
- echo " \n";
+ echo " \n";
echo " | \n";
//echo " \n";
@@ -1268,7 +1268,7 @@
echo " | \n";
if (strlen($row['device_key_uuid']) > 0) {
if (permission_exists('device_key_delete')) {
- echo " $v_link_label_delete\n";
+ echo " $v_link_label_delete\n";
}
}
echo " | \n";
@@ -1313,17 +1313,17 @@
}
//add the primary key uuid
if (strlen($row['device_setting_uuid']) > 0) {
- echo " \n";
+ echo " \n";
}
//show alls rows in the array
echo "
\n";
echo "| \n";
- echo " \n";
+ echo " \n";
echo " | \n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " | \n";
echo "\n";
@@ -1345,7 +1345,7 @@
echo " | \n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " | \n";
if (strlen($text['description-settings']) > 0) {
@@ -1356,10 +1356,10 @@
echo " \n";
if (strlen($row['device_setting_uuid']) > 0) {
if (permission_exists('device_edit')) {
- echo " $v_link_label_edit\n";
+ echo " $v_link_label_edit\n";
}
if (permission_exists('device_delete')) {
- echo " $v_link_label_delete\n";
+ echo " $v_link_label_delete\n";
}
}
echo " | \n";
@@ -1399,8 +1399,8 @@
echo " ".$text['label-device']."\n";
echo "\n";
echo "\n";
- echo " \n";
- echo " \n";
+ echo " \n";
+ echo " \n";
echo " \n";
echo " \n";
echo $text['description-device']."\n";
@@ -1415,7 +1415,7 @@
echo " | \n";
echo "\n";
if (strlen($device_uuid_alternate) == 0) {
- echo " ";
+ echo " ";
}
else {
$label = $device_alternate[0]['device_label'];
@@ -1423,7 +1423,7 @@
if (strlen($label) == 0) { $label = $device_alternate[0]['device_mac_address']; }
echo " \n";
@@ -1440,7 +1440,7 @@
echo " ".$text['label-device_vendor']."\n";
echo " | \n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_vendor']."\n";
echo " | \n";
@@ -1453,7 +1453,7 @@
echo " ".$text['label-device_model']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_model']."\n";
echo " | \n";
@@ -1466,7 +1466,7 @@
echo " ".$text['label-device_firmware_version']."\n";
echo "\n";
echo "\n";
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_firmware_version']."\n";
echo " | \n";
@@ -1488,10 +1488,10 @@
}
foreach ($_SESSION['domains'] as $row) {
if ($row['domain_uuid'] == $domain_uuid) {
- echo " \n";
+ echo " \n";
}
else {
- echo " \n";
+ echo " \n";
}
}
echo " \n";
@@ -1536,12 +1536,12 @@
echo "\n";
echo "\n";
if (permission_exists('device_description')) {
- echo " \n";
+ echo " \n";
echo " \n";
echo $text['description-device_description']."\n";
}
else {
- echo $device_description."\n";
+ echo escape($device_description)."\n";
}
echo " | \n";
@@ -1549,7 +1549,7 @@
echo "
\n";
echo " \n";
if ($action == "update") {
- echo " \n";
+ echo " \n";
}
echo " ";
echo " \n";
|