# try to authenticate user if called from login form
if ($login_action == "do_login") {
- $login = $_POST["login"];
- $password = $_POST["password"];
+ $login = db_escape_string($_POST["login"]);
+ $password = db_escape_string($_POST["password"]);
$remember_me = $_POST["remember_me"];
if (authenticate_user($link, $login, $password)) {
if ($subop == "change-password") {
- $old_pw = $_POST["old_password"];
- $new_pw = $_POST["new_password"];
- $con_pw = $_POST["confirm_password"];
+ $old_pw = db_escape_string($_POST["old_password"]);
+ $new_pw = db_escape_string($_POST["new_password"]);
+ $con_pw = db_escape_string($_POST["confirm_password"]);
if ($old_pw == "") {
print "ERROR: ".__("Old password cannot be blank.");