diff --git a/lib/multiple-results.php b/lib/multiple-results.php
index 9e15f00..00fe582 100644
--- a/lib/multiple-results.php
+++ b/lib/multiple-results.php
@@ -1,4 +1,5 @@
parent.ICEcoder.selectedFiles[j].replace(/\|/g, "/").split("/").length && "/" === targetURL.charAt(parent.ICEcoder.selectedFiles[j].length)))) {
- foundInSelected = true;
+ foundInSelected = true;
}
}
}
@@ -124,8 +127,8 @@ if (true === isset($_GET['target']) && false !== strpos($_GET['target'], "filena
// TODO: get this line working
resultsDisplay +=
targetURL.replace(/\|/g, "/").replace(/_perms/g, "").replace(//g, "" +
- findText.toLowerCase() + "");
+ echo str_replace("/", "\/",strtolower(preg_quote($findText))); ?>/g, "" +
+ parent.ICEcoder.xssClean(findText).toLowerCase() + "");
resultsDisplay += '
';
resultsDisplay += '