From 1235bab5276f8c56ed6ba9cff46563c143c3e240 Mon Sep 17 00:00:00 2001 From: Eric Date: Wed, 18 Nov 2009 20:07:20 +0000 Subject: Escape all login and username characters in database Display correctly usernames (I hope not to have made mistakes) git-svn-id: http://piwigo.org/svn/trunk@4304 68402e56-0260-453c-a942-63ccdbb3a9ee --- admin/comments.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'admin/comments.php') diff --git a/admin/comments.php b/admin/comments.php index cadc3dc67..d4fc89a66 100644 --- a/admin/comments.php +++ b/admin/comments.php @@ -160,7 +160,7 @@ while ($row = mysql_fetch_assoc($result)) } else { - $author_name = $row['username']; + $author_name = stripslashes($row['username']); } $template->append( 'comments', -- cgit v1.2.3