Ignore:
Timestamp:
May 19, 2011, 5:28:40 PM (13 years ago)
Author:
Eric
Message:

use pwg_db_real_escape_string() instead of addslashes()
version 2.20.7 hard coded

File:
1 edited

Legend:

Unmodified
Added
Removed
  • extensions/UserAdvManager/trunk/maintain.inc.php

    r10706 r10942  
    3535    $q = '
    3636INSERT INTO '.CONFIG_TABLE.' (param, value, comment)
    37 VALUES ("UserAdvManager","'.addslashes(serialize($default1)).'","UAM parameters")
     37VALUES ("UserAdvManager","'.pwg_db_real_escape_string(serialize($default1)).'","UAM parameters")
    3838  ;';
    3939    pwg_query($q);
     
    6262    $q = '
    6363INSERT INTO '.CONFIG_TABLE.' (param, value, comment)
    64 VALUES ("UserAdvManager_ConfirmMail","'.addslashes(serialize($default2)).'","UAM ConfirmMail parameters")
     64VALUES ("UserAdvManager_ConfirmMail","'.pwg_db_real_escape_string(serialize($default2)).'","UAM ConfirmMail parameters")
    6565  ;';
    6666    pwg_query($q);
Note: See TracChangeset for help on using the changeset viewer.