summaryrefslogtreecommitdiff
path: root/japanese/perl5/files/patch-lib:CGI.pm
blob: f805d374c336a64a1fc97c1c0667cd43d5ec498f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
--- lib/CGI.pm.orig	Fri Feb 12 09:05:57 1999
+++ lib/CGI.pm	Sat Oct  4 01:14:41 2003
@@ -1413,8 +1413,8 @@
 
     $method = $method || 'POST';
     $enctype = $enctype || &URL_ENCODED;
-    $action = $action ? qq/ACTION="$action"/ : $method eq 'GET' ?
-	'ACTION="'.$self->script_name.'"' : '';
+    $action = $action ? 'ACTION="'.$self->escapeHTML($action).'"' : $method eq 'GET' ?
+	'ACTION="'.$self->escapeHTML($self->script_name).'"' : '';
     my($other) = @other ? " @other" : '';
     $self->{'.parametersToAdd'}={};
     return qq/<FORM METHOD="$method" $action ENCTYPE="$enctype"$other>\n/;