From 649bf3521de4abb61d1d3574fccec0b1a8e0ff47 Mon Sep 17 00:00:00 2001 From: Greg Edwards Date: Sat, 24 May 2014 01:06:16 -0400 Subject: [PATCH] Fixed (rather hilarious) XSS injection possibility on trainer names. --- gts/AllPokemon.aspx.cs | 4 ++-- gts/src/Common.cs | 5 ++++- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/gts/AllPokemon.aspx.cs b/gts/AllPokemon.aspx.cs index e3120876..585502ff 100644 --- a/gts/AllPokemon.aspx.cs +++ b/gts/AllPokemon.aspx.cs @@ -57,7 +57,7 @@ namespace PkmnFoundations.GTS protected String CreateTrainer4(object DataItem) { GtsRecord4 record = (GtsRecord4)DataItem; - return record.TrainerName.Text; + return Common.HtmlEncode(record.TrainerName.Text); } protected String CreateOffer5(object DataItem) @@ -75,7 +75,7 @@ namespace PkmnFoundations.GTS protected String CreateTrainer5(object DataItem) { GtsRecord5 record = (GtsRecord5)DataItem; - return record.TrainerName.Text; + return Common.HtmlEncode(record.TrainerName.Text); } diff --git a/gts/src/Common.cs b/gts/src/Common.cs index d1a45caf..fc16be21 100644 --- a/gts/src/Common.cs +++ b/gts/src/Common.cs @@ -72,6 +72,9 @@ namespace PkmnFoundations.GTS return result.ToArray(); } - + public static string HtmlEncode(string s) + { + return HttpUtility.HtmlEncode(s); + } } } \ No newline at end of file