Ignore:
Timestamp:
2013/06/28 15:24:16 (11 years ago)
Author:
shutta
Message:

#2265 (商品一覧エスケープ漏れ対応)
r22862(脆弱性対応)を2_13-devにもコミット。

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/version-2_13-dev/data/class/pages/products/LC_Page_Products_List.php

    r22857 r22915  
    408408                $arrProducts[$key]['quantity']          = $arrForm['quantity']; 
    409409                $arrProducts[$key]['arrErr']            = $arrErr; 
    410                 $js_fnOnLoad .= "fnSetClassCategories(document.product_form{$arrProducts[$key]['product_id']}, '{$arrForm['classcategory_id2']}');"; 
     410                $classcategory_id2 = SC_Utils_Ex::jsonEncode($arrForm['classcategory_id2']); 
     411                $js_fnOnLoad .= "fnSetClassCategories(document.product_form{$arrProducts[$key]['product_id']}, {$classcategory_id2});"; 
    411412            } 
    412413        } 
Note: See TracChangeset for help on using the changeset viewer.