Permalink
Browse files

BUGFIX Consistently using Convert::raw2sql() instead of DB::getConn()…

…->addslashes() or PHP's deprecated addslashes() for database escaping
  • Loading branch information...
1 parent 5cd1b52 commit b5ea2f68feab41f969a2e6f0589dd55015f74098 @chillu chillu committed Sep 15, 2011
Showing with 2 additions and 2 deletions.
  1. +2 −2 code/AssetAdmin.php
View
4 code/AssetAdmin.php
@@ -378,7 +378,7 @@ function getEditForm($id) {
public function movemarked($urlParams, $form) {
if($_REQUEST['DestFolderID'] && (is_numeric($_REQUEST['DestFolderID']) || ($_REQUEST['DestFolderID']) == 'root')) {
$destFolderID = ($_REQUEST['DestFolderID'] == 'root') ? 0 : $_REQUEST['DestFolderID'];
- $fileList = "'" . ereg_replace(' *, *',"','",trim(addslashes($_REQUEST['FileIDs']))) . "'";
+ $fileList = "'" . ereg_replace(' *, *',"','",trim(Convert::raw2sql($_REQUEST['FileIDs']))) . "'";
$numFiles = 0;
if($fileList != "''") {
@@ -411,7 +411,7 @@ public function movemarked($urlParams, $form) {
* Called and returns in same way as 'save' function
*/
public function deletemarked($urlParams, $form) {
- $fileList = "'" . ereg_replace(' *, *',"','",trim(addslashes($_REQUEST['FileIDs']))) . "'";
+ $fileList = "'" . ereg_replace(' *, *',"','",trim(Convert::raw2sql($_REQUEST['FileIDs']))) . "'";
$numFiles = 0;
$folderID = 0;
$deleteList = '';

0 comments on commit b5ea2f6

Please sign in to comment.