Ignore:
Timestamp:
May 19, 2011, 5:31:34 PM (13 years ago)
Author:
Eric
Message:

r10942 merged from trunk to branch 2.20

File:
1 edited

Legend:

Unmodified
Added
Removed
  • extensions/UserAdvManager/branches/2.20/include/upgradedb.inc.php

    r10707 r10943  
    180180  $query = '
    181181UPDATE '.CONFIG_TABLE.'
    182   SET value = "'.addslashes(serialize($upgrade_UAM)).'"
     182  SET value = "'.pwg_db_real_escape_string(serialize($upgrade_UAM)).'"
    183183  WHERE param = "nbc_UserAdvManager"
    184184;';
     
    191191    $query = '
    192192UPDATE '.CONFIG_TABLE.'
    193   SET value = "'.addslashes(serialize($data)).'"
     193  SET value = "'.pwg_db_real_escape_string(serialize($data)).'"
    194194  WHERE param = "nbc_UserAdvManager_ConfirmMail"
    195195;';
     
    241241  $query = '
    242242      UPDATE '.CONFIG_TABLE.'
    243                         SET value="'.addslashes($update_conf).'"
     243                        SET value="'.pwg_db_real_escape_string($update_conf).'"
    244244                        WHERE param="UserAdvManager_ConfirmMail"
    245245                        LIMIT 1
     
    297297  $query = '
    298298      UPDATE '.CONFIG_TABLE.'
    299                         SET value="'.addslashes($update_conf).'"
     299                        SET value="'.pwg_db_real_escape_string($update_conf).'"
    300300                        WHERE param="UserAdvManager"
    301301                        LIMIT 1
     
    343343  $query = '
    344344      UPDATE '.CONFIG_TABLE.'
    345                         SET value="'.addslashes($update_conf).'"
     345                        SET value="'.pwg_db_real_escape_string($update_conf).'"
    346346                        WHERE param="UserAdvManager"
    347347                        LIMIT 1
     
    389389  $query = '
    390390UPDATE '.CONFIG_TABLE.'
    391 SET value="'.addslashes($update_conf).'"
     391SET value="'.pwg_db_real_escape_string($update_conf).'"
    392392WHERE param="UserAdvManager"
    393393LIMIT 1
     
    446446  $query = '
    447447UPDATE '.CONFIG_TABLE.'
    448 SET value="'.addslashes($update_conf).'"
     448SET value="'.pwg_db_real_escape_string($update_conf).'"
    449449WHERE param="UserAdvManager"
    450450LIMIT 1
Note: See TracChangeset for help on using the changeset viewer.