# Rueckgabe: Bearbeiteter Text (String)\r
\r
function &plain(&$text,$linebreak='<br>') {\r
- $htmltext = htmlentities($text);\r
+ $htmltext = htmlspecialchars($text);\r
$htmltext = preg_replace("/\015\012|\012|\015/",$linebreak,$htmltext);\r
\r
for($x=0;$x<strlen($htmltext);$x++) {\r
# Parameter: Fehlermeldung\r
\r
function show_user_error(&$errmsg) {\r
- global $captcha_enable, $email, $name, $subject, $text, $tpl_user_error;\r
+ global $captcha_enable, $email, $name, $subject, $text, $user_fields, $tpl_user_error;\r
\r
$tpl = new Template;\r
$tpl->read_file($tpl_user_error);\r
\r
$tpl->parse_if_block('CAPTCHA',$captcha_enable);\r
\r
- $tpl->set_var('EMAIL', htmlentities($email));\r
+ $tpl->set_var('EMAIL', htmlspecialchars($email));\r
$tpl->set_var('ERROR', $errmsg);\r
- $tpl->set_var('NAME', htmlentities($name));\r
- $tpl->set_var('SUBJECT',htmlentities($subject));\r
- $tpl->set_var('TEXT', htmlentities($text));\r
+ $tpl->set_var('NAME', htmlspecialchars($name));\r
+ $tpl->set_var('SUBJECT',htmlspecialchars($subject));\r
+ $tpl->set_var('TEXT', htmlspecialchars($text));\r
+\r
+ reset($user_fields);\r
+\r
+ while(list($user_field,$user_field_data) = each($user_fields)) {\r
+ $tpl->set_var($user_field_data['tpl_var'],htmlspecialchars(formdata($user_field)));\r
+ }\r
\r
$tpl->parse();\r
\r