Improved SQL-Injection protection

This commit is contained in:
root 2008-12-28 12:33:29 +00:00
parent b12f68c61d
commit ec17da606c

View file

@ -277,8 +277,8 @@
} }
$hash = make_hash(); $hash = make_hash();
$query = "insert into `disputeemail` set `email`='$email',`memid`='".$_SESSION['profile']['id']."', $query = "insert into `disputeemail` set `email`='$email',`memid`='".intval($_SESSION['profile']['id'])."',
`oldmemid`='$oldmemid',`created`=NOW(),`hash`='$hash',`id`='$emailid', `oldmemid`='$oldmemid',`created`=NOW(),`hash`='$hash',`id`='".intval($emailid)."',
`IP`='".$_SERVER['REMOTE_ADDR']."'"; `IP`='".$_SERVER['REMOTE_ADDR']."'";
mysql_query($query); mysql_query($query);