From 19ce73c88496ca76342c2a07c1b01dc25392c6ff Mon Sep 17 00:00:00 2001 From: Andreas Fischer Date: Mon, 19 Sep 2011 17:20:11 +0200 Subject: [PATCH] [ticket/10370] Call htmlspecialchars() after phpbb_filter_root_path(). PHPBB3-10370 --- phpBB/includes/functions.php | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/phpBB/includes/functions.php b/phpBB/includes/functions.php index 105f2d5fa0..ef13b74f0c 100644 --- a/phpBB/includes/functions.php +++ b/phpBB/includes/functions.php @@ -3407,8 +3407,7 @@ function get_backtrace() $argument = ''; if (!empty($trace['args'][0]) && in_array($trace['function'], array('include', 'require', 'include_once', 'require_once'))) { - $argument = htmlspecialchars($trace['args'][0]); - $argument = phpbb_filter_root_path($argument); + $argument = htmlspecialchars(phpbb_filter_root_path($trace['args'][0])); } $trace['class'] = (!isset($trace['class'])) ? '' : $trace['class'];