diff --git a/app/access_controls/access_control_node_edit.php b/app/access_controls/access_control_node_edit.php index 6acb12fba1..54d7872dd9 100644 --- a/app/access_controls/access_control_node_edit.php +++ b/app/access_controls/access_control_node_edit.php @@ -129,7 +129,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { messages::add($text['message-add']); //redirect the browser - header('Location: access_control_edit.php?id='.$access_control_uuid); + header('Location: access_control_edit.php?id='.escape($access_control_uuid)); return; } //if ($action == "add") @@ -159,7 +159,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { messages::add($text['message-update']); //redirect the browser - header('Location: access_control_edit.php?id='.$access_control_uuid); + header('Location: access_control_edit.php?id='.escape($access_control_uuid)); return; } //if ($action == "update") @@ -167,10 +167,10 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { } //(count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) //pre-populate the form - if (count($_GET)>0 && $_POST["persistformvar"] != "true") { + if (count($_GET) > 0 && $_POST["persistformvar"] != "true") { $access_control_node_uuid = check_str($_GET["id"]); $sql = "select * from v_access_control_nodes "; - $sql .= "where access_control_node_uuid = '$access_control_node_uuid' "; + $sql .= "where access_control_node_uuid = '".$access_control_node_uuid."' "; $prep_statement = $db->prepare(check_sql($sql)); $prep_statement->execute(); $result = $prep_statement->fetchAll(PDO::FETCH_NAMED); @@ -179,7 +179,6 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { $node_cidr = $row["node_cidr"]; $node_domain = $row["node_domain"]; $node_description = $row["node_description"]; - break; //limit to 1 row } unset ($prep_statement); } @@ -193,7 +192,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo "\n"; echo "".$text['title-access_control_node']."

\n"; echo "\n"; - echo " "; + echo " "; echo " "; echo "\n"; echo "\n"; @@ -228,7 +227,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " ".$text['label-node_cidr']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-node_cidr']."\n"; echo "\n"; @@ -239,7 +238,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " ".$text['label-node_domain']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-node_domain']."\n"; echo "\n"; @@ -250,16 +249,16 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " ".$text['label-node_description']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; echo "
\n"; echo $text['description-node_description']."\n"; echo "\n"; echo "\n"; echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; if ($action == "update") { - echo " \n"; + echo " \n"; } echo "
\n"; echo " \n"; @@ -270,4 +269,5 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { //include the footer require_once "resources/footer.php"; + ?>