cvs: php-bugs-web / lstats.php

From: Date: Tue, 15 Jul 2008 22:10:13 +0000
Subject: cvs: php-bugs-web / lstats.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-2111@lists.php.net to get a copy of this message
johannes Tue Jul 15 22:10:13 2008 UTC Modified files: /php-bugs-web lstats.php Log: - Fix escaping, take 2 (thanks Lars Strojny) http://cvs.php.net/viewvc.cgi/php-bugs-web/lstats.php?r1=1.21&r2=1.22&diff_format=u Index: php-bugs-web/lstats.php diff -u php-bugs-web/lstats.php:1.21 php-bugs-web/lstats.php:1.22 --- php-bugs-web/lstats.php:1.21 Tue Jul 15 21:57:32 2008 +++ php-bugs-web/lstats.php Tue Jul 15 22:10:13 2008 @@ -14,14 +14,14 @@ $query = "SELECT count(id) from bugdb WHERE"; if ($phpver > 0) { - $query .= " php_version LIKE '" . $phpver . "%' AND"; + $query .= " php_version LIKE '" . mysql_real_escape_string($phpver) . "%' AND"; } /* Categories which are excluded from bug count */ $excluded = "'Feature/Change Request', 'Systems problem', 'Website Problem', 'PEAR related', 'PECL related', 'Documentation problem', 'Translation problem', 'PHP-GTK related'"; if ($category != '') { - $query.= " $status AND bug_type='$category' "; + $query.= " $status AND bug_type='" . mysql_real_escape_string($category). "' "; } else { $query.= " status='$status' "; } @@ -49,7 +49,7 @@ if(!isset($phpver)) { echo "<h3>Bug stats for both <a href='lstats.php?phpver=4'>PHP 4</a> and <a href='lstats.php?phpver=5'>PHP 5</a>:</h3>\n<pre>\n"; } else { - $phpver = htmlspecialchars($phpver); + $phpver = htmlspecialchars($phpver, ENT_QUOTES); echo "<h3>Bug stats for PHP $phpver:</h3>\n<pre>\n"; }

« previous php.webmaster (#2111) next »