]> git.wh0rd.org Git - tt-rss.git/commitdiff
labels editor: fix quote-escaping
authorAndrew Dolgov <fox@bah.spb.su>
Sat, 19 May 2007 13:51:14 +0000 (14:51 +0100)
committerAndrew Dolgov <fox@bah.spb.su>
Sat, 19 May 2007 13:51:14 +0000 (14:51 +0100)
modules/pref-labels.php

index 5653427003d4026a3299519db3d110948123daf9..3f7b7f80692cfe11480b61ca9b4e82877ad57728 100644 (file)
 
                if ($subop == "editSave") {
 
-                       $sql_exp = trim($_GET["sql_exp"]);
+                       $sql_exp = db_escape_string(trim($_GET["sql_exp"]));
                        $descr = db_escape_string(trim($_GET["description"]));
                        $label_id = db_escape_string($_GET["id"]);
                        
 
                if ($subop == "add") {
 
-                       // no escaping is done here on purpose
-                       $sql_exp = trim($_GET["sql_exp"]);
+                       $sql_exp = db_escape_string(trim($_GET["sql_exp"]));
                        $description = db_escape_string($_GET["description"]);
 
                        if (!$sql_exp || !$description) return;