From c21d6d713e0320b7b61bff1fa0e05bbd250455bb Mon Sep 17 00:00:00 2001 From: thomascube Date: Mon, 3 Nov 2008 08:01:18 +0000 Subject: Don't use addslashes() which could produce unexpected results when magic_quotes_sybase is on --- program/include/main.inc | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'program/include') diff --git a/program/include/main.inc b/program/include/main.inc index 4ed25afaf..43a354919 100644 --- a/program/include/main.inc +++ b/program/include/main.inc @@ -347,6 +347,8 @@ function rep_specialchars_output($str, $enctype='', $mode='', $newlines=TRUE) } $xml_rep_table['"'] = '"'; + $js_rep_table['"'] = '\\"'; + $js_rep_table["'"] = "\\'"; } // encode for XML @@ -359,7 +361,7 @@ function rep_specialchars_output($str, $enctype='', $mode='', $newlines=TRUE) if ($charset!='UTF-8') $str = rcube_charset_convert($str, RCMAIL_CHARSET,$charset); - return preg_replace(array("/\r?\n/", "/\r/", '/<\\//'), array('\n', '\n', '<\\/'), addslashes(strtr($str, $js_rep_table))); + return preg_replace(array("/\r?\n/", "/\r/", '/<\\//'), array('\n', '\n', '<\\/'), strtr($str, $js_rep_table)); } // no encoding given -> return original string -- cgit v1.2.3