Changeset 10940
- Timestamp:
- May 19, 2011, 11:36:09 AM (14 years ago)
- Location:
- extensions/sobre/trunk/admin
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
extensions/sobre/trunk/admin/admin.inc.php
r10480 r10940 19 19 $query = ' 20 20 UPDATE '.CONFIG_TABLE.' 21 SET value = "'. addslashes(serialize($_POST['sbre'])).'"21 SET value = "'.pwg_db_real_escape_string(serialize($_POST['sbre'])).'" 22 22 WHERE param = "Sobre" 23 23 ;'; -
extensions/sobre/trunk/admin/maintain.inc.php
r10317 r10940 17 17 $query = ' 18 18 INSERT INTO ' . CONFIG_TABLE . ' (param,value,comment) 19 VALUES ("Sobre" , "'. addslashes(serialize($config)).'" , "Sobre parameters");';19 VALUES ("Sobre" , "'.pwg_db_real_escape_string(serialize($config)).'" , "Sobre parameters");'; 20 20 21 21 pwg_query($query);
Note: See TracChangeset
for help on using the changeset viewer.