summaryrefslogtreecommitdiffstats
path: root/apps/media
diff options
context:
space:
mode:
authorBjoern Schiessle <schiessle@owncloud.com>2012-06-05 10:46:28 +0200
committerBjoern Schiessle <schiessle@owncloud.com>2012-06-05 10:46:28 +0200
commitd71c4db10aad0b1684087c745dcd10560351efb2 (patch)
tree3b9d470929371d069d5d78dc6fe3db1d5ca54e7f /apps/media
parent564b0358f91df832afdf3a0fd27eaa349508c964 (diff)
downloadnextcloud-server-d71c4db10aad0b1684087c745dcd10560351efb2.tar.gz
nextcloud-server-d71c4db10aad0b1684087c745dcd10560351efb2.zip
xss vulnerability fixed
Diffstat (limited to 'apps/media')
-rw-r--r--apps/media/lib_scanner.php6
1 files changed, 3 insertions, 3 deletions
diff --git a/apps/media/lib_scanner.php b/apps/media/lib_scanner.php
index dc2a8a9beb4..82170e5ca82 100644
--- a/apps/media/lib_scanner.php
+++ b/apps/media/lib_scanner.php
@@ -79,19 +79,19 @@ class OC_MEDIA_SCANNER{
OCP\Util::writeLog('media',"error reading artist tag in '$file'",OCP\Util::WARN);
$artist='unknown';
}else{
- $artist=stripslashes($data['comments']['artist'][0]);
+ $artist=strip_tags(stripslashes($data['comments']['artist'][0]));
}
if(!isset($data['comments']['album'])){
OCP\Util::writeLog('media',"error reading album tag in '$file'",OCP\Util::WARN);
$album='unknown';
}else{
- $album=stripslashes($data['comments']['album'][0]);
+ $album=strip_tags(stripslashes($data['comments']['album'][0]));
}
if(!isset($data['comments']['title'])){
OCP\Util::writeLog('media',"error reading title tag in '$file'",OCP\Util::WARN);
$title='unknown';
}else{
- $title=stripslashes($data['comments']['title'][0]);
+ $title=strip_tags(stripslashes($data['comments']['title'][0]));
}
$size=$data['filesize'];
if (isset($data['comments']['track']))