cvs: pearweb /public_html/bugs stats.php
| From: | Daniel Convissor | Date: | Wed, 30 Jun 2004 17:14:36 +0000 |
| Subject: | cvs: pearweb /public_html/bugs stats.php | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-21320@lists.php.net to get a copy of this message | ||
danielc Wed Jun 30 13:14:36 2004 EDT
Modified files:
/pearweb/public_html/bugs stats.php
Log:
* Use DB::quoteSmart() now that magic quotes is off.
http://cvs.php.net/diff.php/pearweb/public_html/bugs/stats.php?r1=1.25&r2=1.26&ty=u
Index: pearweb/public_html/bugs/stats.php
diff -u pearweb/public_html/bugs/stats.php:1.25 pearweb/public_html/bugs/stats.php:1.26
--- pearweb/public_html/bugs/stats.php:1.25 Wed Jun 30 09:29:03 2004
+++ pearweb/public_html/bugs/stats.php Wed Jun 30 13:14:33 2004
@@ -15,7 +15,7 @@
* @package Bugs
* @copyright Copyright (c) 1997-2004 The PHP Group
* @license http://www.php.net/license/3_0.txt
PHP License
- * @version $Id: stats.php,v 1.25 2004/06/30 13:29:03 dufuz Exp $
+ * @version $Id: stats.php,v 1.26 2004/06/30 17:14:33 danielc Exp $
*/
/**
@@ -76,7 +76,7 @@
$bug_type = '';
} else {
$bug_type = $_GET['bug_type'];
- $where_clause = " AND bug_type = '" . escapeSQL($bug_type) . "'";
+ $where_clause = ' AND bug_type = ' . $dbh->quoteSmart($bug_type);
}
$query .= $where . ' GROUP BY p.name';