diff --git a/dev/Debug.php b/dev/Debug.php
index b7369995e..a4be32329 100644
--- a/dev/Debug.php
+++ b/dev/Debug.php
@@ -532,9 +532,9 @@ class Debug {
} else {
$name = self::full_func_name($item,true);
}
- $result .= "
" . $name . "\n
\n";
+ $result .= "" . htmlentities($name) . "\n
\n";
$result .= isset($item['line']) ? "Line $item[line] of " : '';
- $result .= isset($item['file']) ? basename($item['file']) : '';
+ $result .= isset($item['file']) ? htmlentities(basename($item['file'])) : '';
$result .= "\n";
}
}
diff --git a/dev/DebugView.php b/dev/DebugView.php
index b96061a0f..c19658ae4 100644
--- a/dev/DebugView.php
+++ b/dev/DebugView.php
@@ -96,8 +96,8 @@ class DebugView {
*/
public function writeInfo($title, $subtitle, $description=false) {
echo '';
- echo "
$title
";
- echo "
$subtitle
";
+ echo "
" . Convert::raw2xml($title) . "
";
+ echo "
" . Convert::raw2xml($subtitle) . "
";
if ($description) {
echo "
$description
";
} else {