- $tpl->set_var('NAME', htmlentities($name));\r
- $tpl->set_var('SUBJECT',htmlentities($subject));\r
- $tpl->set_var('TEXT', htmlentities($text));\r
+ $tpl->set_var('NAME', htmlspecialchars($name));\r
+ $tpl->set_var('SUBJECT',htmlspecialchars($subject));\r
+ $tpl->set_var('TEXT', htmlspecialchars($text));\r
+\r
+ reset($user_fields);\r
+\r
+ while(list($user_field,$user_field_data) = each($user_fields)) {\r
+ if(isset($user_field_data['tpl_var']) && $user_field_data['tpl_var'] != '') {\r
+ $tpl_var = $user_field_data['tpl_var'];\r
+ }\r
+ else {\r
+ $tpl_var = 'USER_'.$user_field;\r
+ }\r
+\r
+ $tpl->set_var($tpl_var,htmlspecialchars(formdata($user_field)));\r
+ }\r