cvs: php-bugs-web / lstats.php
| From: | Johannes Schlüter | Date: | Tue, 15 Jul 2008 22:10:13 +0000 |
| Subject: | cvs: php-bugs-web / lstats.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-2111@lists.php.net to get a copy of this message | ||
johannes Tue Jul 15 22:10:13 2008 UTC
Modified files:
/php-bugs-web lstats.php
Log:
- Fix escaping, take 2 (thanks Lars Strojny)
http://cvs.php.net/viewvc.cgi/php-bugs-web/lstats.php?r1=1.21&r2=1.22&diff_format=u
Index: php-bugs-web/lstats.php
diff -u php-bugs-web/lstats.php:1.21 php-bugs-web/lstats.php:1.22
--- php-bugs-web/lstats.php:1.21 Tue Jul 15 21:57:32 2008
+++ php-bugs-web/lstats.php Tue Jul 15 22:10:13 2008
@@ -14,14 +14,14 @@
$query = "SELECT count(id) from bugdb WHERE";
if ($phpver > 0) {
- $query .= " php_version LIKE '" . $phpver . "%' AND";
+ $query .= " php_version LIKE '" . mysql_real_escape_string($phpver) .
"%' AND";
}
/* Categories which are excluded from bug count */
$excluded = "'Feature/Change Request', 'Systems problem', 'Website
Problem', 'PEAR related', 'PECL related', 'Documentation
problem', 'Translation problem', 'PHP-GTK related'";
if ($category != '') {
- $query.= " $status AND bug_type='$category' ";
+ $query.= " $status AND bug_type='" . mysql_real_escape_string($category).
"' ";
} else {
$query.= " status='$status' ";
}
@@ -49,7 +49,7 @@
if(!isset($phpver)) {
echo "<h3>Bug stats for both <a href='lstats.php?phpver=4'>PHP
4</a> and <a href='lstats.php?phpver=5'>PHP
5</a>:</h3>\n<pre>\n";
} else {
- $phpver = htmlspecialchars($phpver);
+ $phpver = htmlspecialchars($phpver, ENT_QUOTES);
echo "<h3>Bug stats for PHP $phpver:</h3>\n<pre>\n";
}