aboutsummaryrefslogtreecommitdiffstats
path: root/apps
diff options
context:
space:
mode:
authorLukas Reschke <lukas@statuscode.ch>2012-07-11 19:14:04 +0200
committerLukas Reschke <lukas@statuscode.ch>2012-07-11 19:14:04 +0200
commitc3fea30811f845fe357b70d5beb511ca4ad42eca (patch)
treedf061036e053369dd336bc1fa6a3f8af9a702daf /apps
parent07efd39d8a1b82f61f5ed429cd713c04c5988788 (diff)
downloadnextcloud-server-c3fea30811f845fe357b70d5beb511ca4ad42eca.tar.gz
nextcloud-server-c3fea30811f845fe357b70d5beb511ca4ad42eca.zip
Sanitizing file names
Diffstat (limited to 'apps')
-rw-r--r--apps/files/js/filelist.js2
1 files changed, 1 insertions, 1 deletions
diff --git a/apps/files/js/filelist.js b/apps/files/js/filelist.js
index e6a9a6883af..3645258f98f 100644
--- a/apps/files/js/filelist.js
+++ b/apps/files/js/filelist.js
@@ -14,7 +14,7 @@ FileList={
var extension=false;
}
html+='<td class="filename" style="background-image:url('+img+')"><input type="checkbox" />';
- html+='<a class="name" href="download.php?file='+$('#dir').val()+'/'+name+'"><span class="nametext">'+basename
+ html+='<a class="name" href="download.php?file='+$('#dir').val().replace(/</, '&lt;').replace(/>/, '&gt;')+'/'+name+'"><span class="nametext">'+basename
if(extension){
html+='<span class="extension">'+extension+'</span>';
}