cvs: pearweb /public_html/bugs search.php
| From: | Daniel Convissor | Date: | Wed, 30 Jun 2004 17:24:47 +0000 |
| Subject: | cvs: pearweb /public_html/bugs search.php | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-21321@lists.php.net to get a copy of this message | ||
danielc Wed Jun 30 13:24:47 2004 EDT
Modified files:
/pearweb/public_html/bugs search.php
Log:
* Use DB::quoteSmart() now that magic quotes is off.
http://cvs.php.net/diff.php/pearweb/public_html/bugs/search.php?r1=1.50&r2=1.51&ty=u
Index: pearweb/public_html/bugs/search.php
diff -u pearweb/public_html/bugs/search.php:1.50 pearweb/public_html/bugs/search.php:1.51
--- pearweb/public_html/bugs/search.php:1.50 Wed Jun 30 12:06:44 2004
+++ pearweb/public_html/bugs/search.php Wed Jun 30 13:24:46 2004
@@ -15,7 +15,7 @@
* @package Bugs
* @copyright Copyright (c) 1997-2004 The PHP Group
* @license http://www.php.net/license/3_0.txt
PHP License
- * @version $Id: search.php,v 1.50 2004/06/30 16:06:44 danielc Exp $
+ * @version $Id: search.php,v 1.51 2004/06/30 17:24:46 danielc Exp $
*/
/**
@@ -95,11 +95,11 @@
$where_clause = ' WHERE bugdb.package_name';
if (count($_GET['package_name']) > 1) {
$where_clause .= " IN ('"
- . join("', '",
escapeSQL($_GET['package_name']))
+ . join("', '",
$dbh->escapeSimple($_GET['package_name']))
. "')";
} else {
- $where_clause .= " = '"
- . escapeSQL($_GET['package_name'][0]) . "'";
+ $where_clause .= ' = '
+ . $dbh->quoteSmart($_GET['package_name'][0]);
}
}
@@ -112,8 +112,8 @@
. join("', '",
escapeSQL($_GET['package_nname']))
. "')";
} else {
- $where_clause .= " <> '"
- . escapeSQL($_GET['package_nname'][0]) . "'";
+ $where_clause .= ' <> '
+ . $dbh->quoteSmart($_GET['package_nname'][0]);
}
}
@@ -184,7 +184,7 @@
$bug_type = '';
} else {
$bug_type = $_GET['bug_type'];
- $where_clause .= " AND bugdb.bug_type = '" . escapeSQL($bug_type) .
"'";
+ $where_clause .= ' AND bugdb.bug_type = ' . $dbh->quoteSmart($bug_type);
}
if (empty($_GET['bug_age']) || !(int)$_GET['bug_age']) {
@@ -200,7 +200,7 @@
} else {
$php_os = $_GET['php_os'];
$where_clause .= " AND bugdb.php_os LIKE '%"
- . escapeSQL($php_os) . "%'";
+ . $dbh->escapeSimple($php_os) . "%'";
}
if (empty($_GET['phpver'])) {
@@ -208,34 +208,34 @@
} else {
$phpver = $_GET['phpver'];
$where_clause .= " AND bugdb.php_version LIKE '"
- . escapeSQL($phpver) . "%'";
+ . $dbh->escapeSimple($phpver) . "%'";
}
if (empty($_GET['assign'])) {
$assign = '';
} else {
$assign = $_GET['assign'];
- $where_clause .= " AND bugdb.assign = '" . escapeSQL($assign) .
"'";
+ $where_clause .= ' AND bugdb.assign = ' . $dbh->quoteSmart($assign);
}
if (empty($_GET['maintain'])) {
$maintain = '';
} else {
$maintain = $_GET['maintain'];
- $where_clause .= " AND maintains.handle = '"
- . escapeSQL($maintain) . "'";
+ $where_clause .= ' AND maintains.handle = '
+ . $dbh->quoteSmart($maintain);
}
if (empty($_GET['author_email'])) {
$author_email = '';
} else {
$author_email = $_GET['author_email'];
- $where_clause .= " AND bugdb.email = '"
- . escapeSQL($author_email) . "'";
+ $where_clause .= ' AND bugdb.email = '
+ . $dbh->quoteSmart($author_email);
}
- $where_clause .= " AND (packages.package_type = '"
- . escapeSQL($site) . "'";
+ $where_clause .= ' AND (packages.package_type = '
+ . $dbh->quoteSmart($site);
if ($pseudo = array_intersect($pseudo_pkgs, $_GET['package_name'])) {
$where_clause .= " OR bugdb.package_name";