]> git.wh0rd.org Git - tt-rss.git/commitdiff
fix security issue in view
authorAndrew Dolgov <fox@madoka.spb.ru>
Tue, 16 May 2006 11:48:07 +0000 (12:48 +0100)
committerAndrew Dolgov <fox@madoka.spb.ru>
Tue, 16 May 2006 11:48:07 +0000 (12:48 +0100)
backend.php

index 914a04ba6103af7adcdee41ad4316a2955d5be58..51551314e487f12033e375ced788cb3c6c0dfff2 100644 (file)
                        num_comments,
                        author
                        FROM ttrss_entries,ttrss_user_entries
-                       WHERE   id = '$id' AND ref_id = id");
+                       WHERE   id = '$id' AND ref_id = id AND owner_uid = " . $_SESSION["uid"]);
 
                print "<html><head>
                        <title>Tiny Tiny RSS : Article $id</title>