4f1aaa591d14ef02e785e2ae05f86c49129104af
galt
Wed Sep 21 14:27:01 2016 -0700
fix XSS textarea in hgBlat. refs #17782.
diff --git src/hg/hgBlat/hgBlat.c src/hg/hgBlat/hgBlat.c
index 03b96b3..eea2f90 100644
--- src/hg/hgBlat/hgBlat.c
+++ src/hg/hgBlat/hgBlat.c
@@ -733,31 +733,31 @@
printf("
\n");
printBlatAssemblyListHtml(db);
printf(" \n");
printf("\n");
cgiMakeDropList("type", typeList, ArraySize(typeList), NULL);
printf(" \n");
printf("\n");
cgiMakeDropList("sort", sortList, ArraySize(sortList), cartOptionalString(cart, "sort"));
printf(" \n");
printf("\n");
cgiMakeDropList("output", outputList, ArraySize(outputList), cartOptionalString(cart, "output"));
printf(" \n");
printf("\n\n");
userSeq = cartUsualString(cart, "userSeq", "");
printf("\n");
-printf("\n", userSeq);
+htmlPrintf("\n", userSeq);
printf(" \n");
printf(" \n\n");
printf("\n");
printf(" \n");
printf(" \n");
printf(" \n");
printf(" \n");
printf(" \n\n");
puts("\n"
"Paste in a query sequence to find its location in the\n"
"the genome. Multiple sequences may be searched \n"
"if separated by lines starting with '>' followed by the sequence name.\n"
" \n"
" \n"