gitweb: No error messages with unescaped/unprotected user input

Signed-off-by: Jakub Narebski <jnareb@gmail.com>
Signed-off-by: Junio C Hamano <junkio@cox.net>
This commit is contained in:
Jakub Narebski 2006-08-05 13:15:24 +02:00 committed by Junio C Hamano
parent cac4bd94fb
commit e2860ead31

View File

@ -1265,7 +1265,7 @@ sub git_diff_print {
sub git_project_list {
my $order = $cgi->param('o');
if (defined $order && $order !~ m/project|descr|owner|age/) {
die_error(undef, "Invalid order parameter '$order'");
die_error(undef, "Unknown order parameter");
}
my @list = git_read_projects();