";
echo "
";
if(isset($error) && $error) //an error occured during the action, so show an error message
- echo $lang['err'].": ".$db->getError()."
".$lang['bug_report'].' '.PROJECT_BUGTRACKER_LINK;
+ echo $lang['err'].": ".htmlencode($db->getError())."
".$lang['bug_report'].' '.PROJECT_BUGTRACKER_LINK;
else //action was performed successfully - show success message
echo $completed;
echo "
";
@@ -1841,6 +1877,7 @@ if(isset($_GET['action']) && !isset($_GET['confirm']))
$num = intval($_POST['tablefields']);
$name = $_POST['tablename'];
echo "