luci/modules/luci-mod-admin-full/luasrc/view/admin_system
Jo-Philipp Wich bfc98bec4d luci-mod-admin-full: escape display parameter
Prevent reflected XSS through the reset button by url encoding the
display parameter.

Signed-off-by: Jo-Philipp Wich <jo@mein.io>
2018-04-05 23:03:01 +02:00
..
applyreboot.htm Globally convert headline anchors into name attributes. 2015-10-06 13:30:33 +02:00
backupfiles.htm Globally replace luci.dispatcher.build_url(...) with url(...) invocations 2015-10-07 19:07:36 +02:00
clock_status.htm luci-mod-admin-full: protect clock, flash and opkg ops with submit token 2015-10-20 21:04:46 +02:00
flashops.htm luci-mod-admin-full: add hint on backup restore 2018-03-01 12:33:43 +01:00
ipkg.htm Globally replace luci.dispatcher.build_url(...) with url(...) invocations 2015-10-07 19:07:36 +02:00
packages.htm luci-mod-admin-full: escape display parameter 2018-04-05 23:03:01 +02:00
reboot.htm luci-mod-admin-full: switch to POST action for reboot 2015-10-07 01:54:56 +02:00
upgrade.htm luci-mod-admin-full: tweak checksum item presentation 2016-08-24 11:46:20 +03:00