diff --git a/app/access_controls/access_control_node_edit.php b/app/access_controls/access_control_node_edit.php index 6acb12fba1..54d7872dd9 100644 --- a/app/access_controls/access_control_node_edit.php +++ b/app/access_controls/access_control_node_edit.php @@ -129,7 +129,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { messages::add($text['message-add']); //redirect the browser - header('Location: access_control_edit.php?id='.$access_control_uuid); + header('Location: access_control_edit.php?id='.escape($access_control_uuid)); return; } //if ($action == "add") @@ -159,7 +159,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { messages::add($text['message-update']); //redirect the browser - header('Location: access_control_edit.php?id='.$access_control_uuid); + header('Location: access_control_edit.php?id='.escape($access_control_uuid)); return; } //if ($action == "update") @@ -167,10 +167,10 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { } //(count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) //pre-populate the form - if (count($_GET)>0 && $_POST["persistformvar"] != "true") { + if (count($_GET) > 0 && $_POST["persistformvar"] != "true") { $access_control_node_uuid = check_str($_GET["id"]); $sql = "select * from v_access_control_nodes "; - $sql .= "where access_control_node_uuid = '$access_control_node_uuid' "; + $sql .= "where access_control_node_uuid = '".$access_control_node_uuid."' "; $prep_statement = $db->prepare(check_sql($sql)); $prep_statement->execute(); $result = $prep_statement->fetchAll(PDO::FETCH_NAMED); @@ -179,7 +179,6 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { $node_cidr = $row["node_cidr"]; $node_domain = $row["node_domain"]; $node_description = $row["node_description"]; - break; //limit to 1 row } unset ($prep_statement); } @@ -193,7 +192,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo "