Use SCRIPT_NAME instead of PHP_SELF which won't send the PATH_INFO, this prevents XSS in old browsers. Thanks to Nico Golde.
parent
f1cabdd8e0
commit
6ef5edf5ea
Loading…
Reference in New Issue