5bb59d7
--- init.php.orig	2012-11-16 14:02:47.737621181 -0100
5bb59d7
+++ init.php	2012-11-16 14:03:49.680340099 -0100
5bb59d7
@@ -67,11 +67,11 @@
5bb59d7
     unset($url);
5bb59d7
 }
5bb59d7
 
5bb59d7
-// Change project name to lower case
5bb59d7
-if (isset($_GET['project'])) $_GET['project'] = strtolower($_GET['project']);
5bb59d7
-if (isset($_POST['project'])) $_POST['project'] = strtolower($_POST['project']);
5bb59d7
-if (isset($_GET['paste_project'])) $_GET['paste_project'] = strtolower($_GET['paste_project']);
5bb59d7
-if (isset($_POST['paste_project'])) $_POST['paste_project'] = strtolower($_POST['paste_project']);
5bb59d7
+// Change project name to lower case and escape it
5bb59d7
+if (isset($_GET['project'])) $_GET['project'] = htmlspecialchars(strtolower($_GET['project']));
5bb59d7
+if (isset($_POST['project'])) $_POST['project'] = htmlspecialchars(strtolower($_POST['project']));
5bb59d7
+if (isset($_GET['paste_project'])) $_GET['paste_project'] = htmlspecialchars(strtolower($_GET['paste_project']));
5bb59d7
+if (isset($_POST['paste_project'])) $_POST['paste_project'] = htmlspecialchars(strtolower($_POST['paste_project']));
5bb59d7
 
5bb59d7
 // Set up the db connection
5bb59d7
 $db->connect();