瀏覽代碼

SQL injection fix. This is serious I think.

stekkel 21 年之前
父節點
當前提交
70d069a922
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      functions/abook_database.php

+ 1 - 1
functions/abook_database.php

@@ -174,7 +174,7 @@ class abook_database extends addressbook_backend {
         }
         }
          
          
         $query = sprintf("SELECT * FROM %s WHERE owner='%s' AND nickname='%s'",
         $query = sprintf("SELECT * FROM %s WHERE owner='%s' AND nickname='%s'",
-                         $this->table, $this->owner, $alias);
+                         $this->table, $this->owner, $this->dbh->quoteString($alias));
 
 
         $res = $this->dbh->query($query);
         $res = $this->dbh->query($query);