Skip to content
This repository has been archived by the owner on Dec 13, 2022. It is now read-only.

FIX(security): vulnerabilities in color_picker #12017

Open
wants to merge 3 commits into
base: develop
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 30 additions & 26 deletions www/include/common/javascript/color_picker.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,38 +3,38 @@
* Copyright 2005-2015 Centreon
* Centreon is developped by : Julien Mathis and Romain Le Merlus under
* GPL Licence 2.0.
*
* This program is free software; you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free Software
*
* This program is free software; you can redistribute it and/or modify it under
* the terms of the GNU General Public License as published by the Free Software
* Foundation ; either version 2 of the License.
*
*
* This program is distributed in the hope that it will be useful, but WITHOUT ANY
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
* PARTICULAR PURPOSE. See the GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License along with
*
* You should have received a copy of the GNU General Public License along with
* this program; if not, see <http://www.gnu.org/licenses>.
*
* Linking this program statically or dynamically with other modules is making a
* combined work based on this program. Thus, the terms and conditions of the GNU
*
* Linking this program statically or dynamically with other modules is making a
* combined work based on this program. Thus, the terms and conditions of the GNU
* General Public License cover the whole combination.
*
* As a special exception, the copyright holders of this program give Centreon
* permission to link this program with independent modules to produce an executable,
* regardless of the license terms of these independent modules, and to copy and
* distribute the resulting executable under terms of Centreon choice, provided that
* Centreon also meet, for each linked independent module, the terms and conditions
* of the license of that module. An independent module is a module which is not
* derived from this program. If you modify this program, you may extend this
*
* As a special exception, the copyright holders of this program give Centreon
* permission to link this program with independent modules to produce an executable,
* regardless of the license terms of these independent modules, and to copy and
* distribute the resulting executable under terms of Centreon choice, provided that
* Centreon also meet, for each linked independent module, the terms and conditions
* of the license of that module. An independent module is a module which is not
* derived from this program. If you modify this program, you may extend this
* exception to your version of the program, but you are not obliged to do so. If you
* do not wish to do so, delete this exception statement from your version.
*
*
* For more information : [email protected]
*
*
* SVN : $URL$
* SVN : $Id$
*
*/
require_once __DIR__ . '/../../../class/HtmlAnalyzer.php';

$n = "";
$name = "";
Expand Down Expand Up @@ -64,15 +64,19 @@ function filter_get($str)
$hcolor = filter_get($_GET["hcolor"]);
}
}
$name1 = $n."";
$name2 = $n."_color";
$n = htmlspecialchars($n, ENT_QUOTES, 'UTF-8');
$name = htmlspecialchars($name, ENT_QUOTES, 'UTF-8');
$title = htmlspecialchars($title, ENT_QUOTES, 'UTF-8');
$hcolor = htmlspecialchars($hcolor, ENT_QUOTES, 'UTF-8');
$name1 = $n . "";
$name2 = $n . "_color";

?>
<html>
<head>
<title>Color Picker</title>
<style type="text/css">
body { font-size: 12px; font-family: Verdana, Sans-Serif; text-align:center; background-color:#FFFFFF; color:navy;}
body { font-size: 12px; font-family: Verdana, Sans-Serif; text-align:center; background-color:#FFFFFF; color:navy;}
td { font-size: 12px; font-family: Verdana, Sans-Serif; text-align:center; background-color:#FFFFFF}
.table_black_border {border-style:solid; border-width:1px; border-color:#000000;}
</style>
Expand Down Expand Up @@ -204,8 +208,8 @@ function send_color()
</head>
<body>
<form name="colpick_form" action="#" method="post">
<h2><?php echo $title; ?></h2>
<h3><?php echo $name; ?></h3>
<h2><?php echo $title; ?></h2>
<h3><?php echo $name; ?></h3>
<table border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -157,7 +157,8 @@ function activate_color_selection(e) {

jQuery(document).ready(function() {
jQuery('input[name$="_color"]').click(function(e) {
popup_color_picker(jQuery(this).attr('name').replace(/_color$/g, ''), 'Line color');
let name = jQuery(this).attr('name');
popup_color_picker(name.replace(/_color$/g, ''), name);
});
jQuery('input[name$="_color"]').click(activate_color_selection);
activate_color_selection.apply(jQuery('input[name$="_color"]:checked'));
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -371,7 +371,8 @@ function popup_color_picker(t,name)
{
var width = 400;
var height = 300;
window.open('./include/common/javascript/color_picker.php?n=' + t + '&name=' + name,
var title = name.includes("area") ? "Area color" : "Line color";
window.open('./include/common/javascript/color_picker.php?n=' + t + '&name=' + name + "&title=" + title,
'cp',
'resizable=no, location=no, width=' + width + ', height=' + height +
', menubar=no, status=yes, scrollbars=no, menubar=no'
Expand Down