cvs: pearweb /public_html/bugs search.php

From: Date: Wed, 30 Jun 2004 17:24:47 +0000
Subject: cvs: pearweb /public_html/bugs search.php
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-21321@lists.php.net to get a copy of this message
danielc Wed Jun 30 13:24:47 2004 EDT Modified files: /pearweb/public_html/bugs search.php Log: * Use DB::quoteSmart() now that magic quotes is off. http://cvs.php.net/diff.php/pearweb/public_html/bugs/search.php?r1=1.50&r2=1.51&ty=u Index: pearweb/public_html/bugs/search.php diff -u pearweb/public_html/bugs/search.php:1.50 pearweb/public_html/bugs/search.php:1.51 --- pearweb/public_html/bugs/search.php:1.50 Wed Jun 30 12:06:44 2004 +++ pearweb/public_html/bugs/search.php Wed Jun 30 13:24:46 2004 @@ -15,7 +15,7 @@ * @package Bugs * @copyright Copyright (c) 1997-2004 The PHP Group * @license http://www.php.net/license/3_0.txt PHP License - * @version $Id: search.php,v 1.50 2004/06/30 16:06:44 danielc Exp $ + * @version $Id: search.php,v 1.51 2004/06/30 17:24:46 danielc Exp $ */ /** @@ -95,11 +95,11 @@ $where_clause = ' WHERE bugdb.package_name'; if (count($_GET['package_name']) > 1) { $where_clause .= " IN ('" - . join("', '", escapeSQL($_GET['package_name'])) + . join("', '", $dbh->escapeSimple($_GET['package_name'])) . "')"; } else { - $where_clause .= " = '" - . escapeSQL($_GET['package_name'][0]) . "'"; + $where_clause .= ' = ' + . $dbh->quoteSmart($_GET['package_name'][0]); } } @@ -112,8 +112,8 @@ . join("', '", escapeSQL($_GET['package_nname'])) . "')"; } else { - $where_clause .= " <> '" - . escapeSQL($_GET['package_nname'][0]) . "'"; + $where_clause .= ' <> ' + . $dbh->quoteSmart($_GET['package_nname'][0]); } } @@ -184,7 +184,7 @@ $bug_type = ''; } else { $bug_type = $_GET['bug_type']; - $where_clause .= " AND bugdb.bug_type = '" . escapeSQL($bug_type) . "'"; + $where_clause .= ' AND bugdb.bug_type = ' . $dbh->quoteSmart($bug_type); } if (empty($_GET['bug_age']) || !(int)$_GET['bug_age']) { @@ -200,7 +200,7 @@ } else { $php_os = $_GET['php_os']; $where_clause .= " AND bugdb.php_os LIKE '%" - . escapeSQL($php_os) . "%'"; + . $dbh->escapeSimple($php_os) . "%'"; } if (empty($_GET['phpver'])) { @@ -208,34 +208,34 @@ } else { $phpver = $_GET['phpver']; $where_clause .= " AND bugdb.php_version LIKE '" - . escapeSQL($phpver) . "%'"; + . $dbh->escapeSimple($phpver) . "%'"; } if (empty($_GET['assign'])) { $assign = ''; } else { $assign = $_GET['assign']; - $where_clause .= " AND bugdb.assign = '" . escapeSQL($assign) . "'"; + $where_clause .= ' AND bugdb.assign = ' . $dbh->quoteSmart($assign); } if (empty($_GET['maintain'])) { $maintain = ''; } else { $maintain = $_GET['maintain']; - $where_clause .= " AND maintains.handle = '" - . escapeSQL($maintain) . "'"; + $where_clause .= ' AND maintains.handle = ' + . $dbh->quoteSmart($maintain); } if (empty($_GET['author_email'])) { $author_email = ''; } else { $author_email = $_GET['author_email']; - $where_clause .= " AND bugdb.email = '" - . escapeSQL($author_email) . "'"; + $where_clause .= ' AND bugdb.email = ' + . $dbh->quoteSmart($author_email); } - $where_clause .= " AND (packages.package_type = '" - . escapeSQL($site) . "'"; + $where_clause .= ' AND (packages.package_type = ' + . $dbh->quoteSmart($site); if ($pseudo = array_intersect($pseudo_pkgs, $_GET['package_name'])) { $where_clause .= " OR bugdb.package_name";

« previous php.pear.cvs (#21321) next »