[TYPO3-core] RFC #13570: Bug: HTML validation error in the BE with the ajax.php inclusion

Oliver Klee typo3-german-02 at oliverklee.de
Thu Feb 18 11:50:01 CET 2010


Hi,

Steffen Kamper schrieb:
> in all other places the use of & was rejected, should use HSC. So i
> also would use it here:
> htmlspecialchars('ajax.php?ajaxID=ExtDirect::getAPI&namespace=TYPO3.Backend')

I've attached an updated patch.


Oli
-- 
Certified TYPO3 Integrator | TYPO3 Security Team Member
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 13570-v2.diff
Type: text/x-patch
Size: 482 bytes
Desc: not available
URL: <http://lists.typo3.org/pipermail/typo3-team-core/attachments/20100218/0268eb1d/attachment.bin>


More information about the TYPO3-team-core mailing list