diff --git a/features/http-auth.xml b/features/http-auth.xml index 2126b1b5ef..7f10c0d8ec 100644 --- a/features/http-auth.xml +++ b/features/http-auth.xml @@ -198,11 +198,11 @@ if (!isset($_SERVER['PHP_AUTH_USER']) || ($_POST['SeenBefore'] == 1 && $_POST['OldAuth'] == $_SERVER['PHP_AUTH_USER'])) { authenticate(); } else { - echo "

Welcome: {$_SERVER['PHP_AUTH_USER']}
"; - echo "Old: {$_REQUEST['OldAuth']}"; - echo "

\n"; + echo "

Welcome: " . htmlspecialchars($_SERVER['PHP_AUTH_USER']) . "
"; + echo "Old: " . htmlspecialchars($_REQUEST['OldAuth']); + echo "\n"; echo "\n"; - echo "\n"; + echo "\n"; echo "\n"; echo "

\n"; }