Improved parameter checking

pull/1/head
root 16 years ago
parent a71504fc3a
commit ae56e3ca62

@ -53,7 +53,7 @@
$password = mysql_escape_string(stripslashes(trim($_REQUEST["pword"])));
$URL = mysql_escape_string(trim($_REQUEST["notaryURL"]));
$CN = mysql_escape_string($_SESSION['_config']['CN']);
$memid = mysql_escape_string($_SESSION['_config']['uid']);
$memid = intval($_SESSION['_config']['uid']);
$user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='$memid'"));
$tmp = mysql_fetch_assoc(mysql_query("select sum(`points`) as `points` from `notary` where `to`='$memid'"));

Loading…
Cancel
Save