Skip to content

Commit

Permalink
Fix security issue in all CGI script clwarn.cgi*, patch from Zoltan B…
Browse files Browse the repository at this point in the history
…orbely - Andrews Kft
  • Loading branch information
darold committed Jun 20, 2012
1 parent cafb630 commit 5806d10
Show file tree
Hide file tree
Showing 6 changed files with 25 additions and 22 deletions.
8 changes: 4 additions & 4 deletions cgi-bin/clwarn.cgi
Expand Up @@ -7,11 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $source = $cgi->param('source') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = $cgi->param('user') || '';
my $user = CGI::escapeHTML($cgi->param('user')) || '';


my $TITLE_VIRUS = "SquidClamAv $VERSION: Virus detection";
Expand Down
8 changes: 4 additions & 4 deletions cgi-bin/clwarn.cgi.de_DE
Expand Up @@ -7,11 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $source = $cgi->param('source') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = $cgi->param('user') || '';
my $user = CGI::escapeHTML($cgi->param('user')) || '';

my $TITLE_VIRUS = "Virus Alarm";
my $subtitle = 'enthält folgenden Virus';
Expand Down
8 changes: 4 additions & 4 deletions cgi-bin/clwarn.cgi.en_EN
Expand Up @@ -7,11 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $source = $cgi->param('source') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = $cgi->param('user') || '';
my $user = CGI::escapeHTML($cgi->param('user')) || '';

my $TITLE_VIRUS = "SquidClamAv $VERSION: Virus detection";
my $subtitle = 'contains the virus';
Expand Down
8 changes: 4 additions & 4 deletions cgi-bin/clwarn.cgi.fr_FR
Expand Up @@ -7,11 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $source = $cgi->param('source') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = $cgi->param('user') || '';
my $user = CGI::escapeHTML($cgi->param('user')) || '';

my $TITLE_VIRUS = "SquidClamAv $VERSION: Virus detection";
my $subtitle = 'contient le virus';
Expand Down
7 changes: 5 additions & 2 deletions cgi-bin/clwarn.cgi.pt_BR
Expand Up @@ -7,8 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = CGI::escapeHTML($cgi->param('user')) || '';

my $TITLE_VIRUS = "SquidClamAv $VERSION: Foi detectado um vírus!";
my $subtitle = 'está infectada pelo vírus';
Expand Down
8 changes: 4 additions & 4 deletions cgi-bin/clwarn.cgi.ru_RU
Expand Up @@ -7,11 +7,11 @@ my $VERSION = '6.6';

my $cgi = new CGI;

my $url = $cgi->param('url') || '';
my $virus = $cgi->param('virus') || '';
my $source = $cgi->param('source') || '';
my $url = CGI::escapeHTML($cgi->param('url')) || '';
my $virus = CGI::escapeHTML($cgi->param('virus')) || '';
my $source = CGI::escapeHTML($cgi->param('source')) || '';
$source =~ s/\/-//;
my $user = $cgi->param('user') || '';
my $user = CGI::escapeHTML($cgi->param('user')) || '';

my $TITLE_VIRUS = "SquidClamAv $VERSION: Обнаружен вирус!";
my $subtitle = 'содержит вирус';
Expand Down

0 comments on commit 5806d10

Please sign in to comment.