also escape HTML in the file name
This commit is contained in:
parent
d6a8bb9322
commit
f1a36d48b5
1 changed files with 1 additions and 1 deletions
|
|
@ -163,7 +163,7 @@
|
|||
</tr>
|
||||
#for $file in $files
|
||||
<tr class="$util.rowToggle($self)">
|
||||
<td><a href="fileinfo?rpmID=$rpm.id&filename=$urllib.quote($file.name)">$file.name</a></td><td>$file.size</td>
|
||||
<td><a href="fileinfo?rpmID=$rpm.id&filename=$urllib.quote($file.name)">$util.escapeHTML($file.name)</a></td><td>$file.size</td>
|
||||
</tr>
|
||||
#end for
|
||||
</table>
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue