Browse Source

fix up self xss in contact form JS

master
David Miller 9 years ago
parent
commit
674f0a3fda
  1. 4
      js/contact_me.js
  2. 2
      mail/contact_me.php

4
js/contact_me.js

@ -47,7 +47,7 @@ $(function() { @@ -47,7 +47,7 @@ $(function() {
$('#success').html("<div class='alert alert-danger'>");
$('#success > .alert-danger').html("<button type='button' class='close' data-dismiss='alert' aria-hidden='true'>&times;")
.append("</button>");
$('#success > .alert-danger').append("<strong>Sorry " + firstName + ", it seems that my mail server is not responding. Please try again later!");
$('#success > .alert-danger').append($("<strong>").text("Sorry " + firstName + ", it seems that my mail server is not responding. Please try again later!"));
$('#success > .alert-danger').append('</div>');
//clear all fields
$('#contactForm').trigger("reset");
@ -69,4 +69,4 @@ $(function() { @@ -69,4 +69,4 @@ $(function() {
/*When clicking on Full hide fail/success boxes */
$('#name').focus(function() {
$('#success').html('');
});
});

2
mail/contact_me.php

@ -23,4 +23,4 @@ $headers = "From: noreply@yourdomain.com\n"; // This is the email address the ge @@ -23,4 +23,4 @@ $headers = "From: noreply@yourdomain.com\n"; // This is the email address the ge
$headers .= "Reply-To: $email_address";
mail($to,$email_subject,$email_body,$headers);
return true;
?>
?>
Loading…
Cancel
Save