diff --git a/app/fax/fax.php b/app/fax/fax.php
index f93da65b07..d40615a118 100644
--- a/app/fax/fax.php
+++ b/app/fax/fax.php
@@ -146,46 +146,46 @@
echo "
\n";
echo " | ";
if (permission_exists('fax_extension_edit')) {
- echo "".$row['fax_name']."";
+ echo "".escape($row['fax_name'])."";
}
else {
- echo $row['fax_name'];
+ echo escape($row['fax_name']);
}
echo " | \n";
- echo " ".$row['fax_extension']." | \n";
- echo " ".$fax_email." | \n";
+ echo " ".escape($row['fax_extension'])." | \n";
+ echo " ".escape($fax_email)." | \n";
echo " ";
if (permission_exists('fax_send')) {
- echo " ".$text['label-new']." ";
+ echo " ".escape($text['label-new'])." ";
}
if (permission_exists('fax_inbox_view')) {
if ($row['fax_email_inbound_subject_tag'] != '') {
$file = "fax_files_remote.php";
- $box = $row['fax_email_connection_mailbox'];
+ $box = escape($row['fax_email_connection_mailbox']);
}
else {
$file = "fax_files.php";
$box = 'inbox';
}
- echo " ".$text['label-inbox']." ";
+ echo " ".$text['label-inbox']." ";
}
if (permission_exists('fax_sent_view')) {
- echo " ".$text['label-sent']." ";
+ echo " ".$text['label-sent']." ";
}
if (permission_exists('fax_log_view')) {
- echo " ".$text['label-log']."";
+ echo " ".$text['label-log']."";
}
if (permission_exists('fax_active_view')) {
- echo " ".$text['label-active']."";
+ echo " ".$text['label-active']."";
}
echo " | \n";
- echo " ".$row['fax_description']." | \n";
+ echo " ".escape($row['fax_description'])." | \n";
echo " ";
if (permission_exists('fax_extension_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('fax_extension_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";
@@ -200,7 +200,7 @@
echo " \n";
echo " \n";
echo " | | \n";
- echo " $paging_controls | \n";
+ echo " $paging_controls | \n";
echo " ";
if (permission_exists('fax_extension_add')) {
echo "$v_link_label_add";
@@ -215,4 +215,5 @@
//show the footer
require_once "resources/footer.php";
+
?>
|