]> git.mxchange.org Git - friendica.git/commitdiff
block injection vector
authorfriendica <info@friendica.com>
Wed, 27 Feb 2013 01:33:18 +0000 (17:33 -0800)
committerfriendica <info@friendica.com>
Wed, 27 Feb 2013 01:33:18 +0000 (17:33 -0800)
boot.php
include/bbcode.php
util/messages.po

index bb721530376b7601162e2bae722edc939135979c..54e3ec9182ff113042899f9504cc40d556b1b93e 100644 (file)
--- a/boot.php
+++ b/boot.php
@@ -12,7 +12,7 @@ require_once('library/Mobile_Detect/Mobile_Detect.php');
 require_once('include/features.php');
 
 define ( 'FRIENDICA_PLATFORM',     'Friendica');
-define ( 'FRIENDICA_VERSION',      '3.1.1619' );
+define ( 'FRIENDICA_VERSION',      '3.1.1623' );
 define ( 'DFRN_PROTOCOL_VERSION',  '2.23'    );
 define ( 'DB_UPDATE_VERSION',      1163      );
 define ( 'EOL',                    "<br />\r\n"     );
index a587d8c38075e5f6da2dfc066801492d8f6f8eaa..d9a1192d67bede8a2bb551020142b47115b61ed8 100644 (file)
@@ -652,20 +652,20 @@ function bbcode($Text,$preserve_nl = false, $tryoembed = true, $simplehtml = fal
        // Only do it when it has to be done - for performance reasons
        // Update: Now it is done every time - since bad structured html can break a whole page
        //if (!$tryoembed) {
-               $doc = new DOMDocument();
-               $doc->preserveWhiteSpace = false;
+//             $doc = new DOMDocument();
+//             $doc->preserveWhiteSpace = false;
 
-               $Text = mb_convert_encoding($Text, 'HTML-ENTITIES', "UTF-8");
+//             $Text = mb_convert_encoding($Text, 'HTML-ENTITIES', "UTF-8");
 
-               $doctype = '<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">';
-               @$doc->loadHTML($doctype."<html><body>".$Text."</body></html>");
+//             $doctype = '<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">';
+//             @$doc->loadHTML($doctype."<html><body>".$Text."</body></html>");
 
-               $Text = $doc->saveHTML();
-               $Text = str_replace(array("<html><body>", "</body></html>", $doctype), array("", "", ""), $Text);
+//             $Text = $doc->saveHTML();
+//             $Text = str_replace(array("<html><body>", "</body></html>", $doctype), array("", "", ""), $Text);
 
-               $Text = str_replace('<br></li>','</li>', $Text);
+//             $Text = str_replace('<br></li>','</li>', $Text);
 
-               $Text = mb_convert_encoding($Text, "UTF-8", 'HTML-ENTITIES');
+//             $Text = mb_convert_encoding($Text, "UTF-8", 'HTML-ENTITIES');
        //}
 
        call_hooks('bbcode',$Text);
index 53e251a21f30b7d04d7a1652dec44ddb0c443db9..da69e320b6aebe8b1694746607d1cd77e42af93d 100644 (file)
@@ -6,9 +6,9 @@
 #, fuzzy
 msgid ""
 msgstr ""
-"Project-Id-Version: 3.1.1619\n"
+"Project-Id-Version: 3.1.1623\n"
 "Report-Msgid-Bugs-To: \n"
-"POT-Creation-Date: 2013-02-22 00:00-0800\n"
+"POT-Creation-Date: 2013-02-26 00:00-0800\n"
 "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
 "Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
 "Language-Team: LANGUAGE <LL@li.org>\n"
@@ -9839,6 +9839,10 @@ msgstr ""
 msgid "Textareas font size"
 msgstr ""
 
+#: ../../index.php:400
+msgid "toggle mobile"
+msgstr ""
+
 #: ../../boot.php:650
 msgid "Delete this item?"
 msgstr ""
@@ -9960,7 +9964,3 @@ msgstr ""
 #: ../../boot.php:1895
 msgid "Only You Can See This"
 msgstr ""
-
-#: ../../index.php:400
-msgid "toggle mobile"
-msgstr ""