From 1235bab5276f8c56ed6ba9cff46563c143c3e240 Mon Sep 17 00:00:00 2001 From: Eric Date: Wed, 18 Nov 2009 20:07:20 +0000 Subject: Escape all login and username characters in database Display correctly usernames (I hope not to have made mistakes) git-svn-id: http://piwigo.org/svn/trunk@4304 68402e56-0260-453c-a942-63ccdbb3a9ee --- admin/user_list.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'admin/user_list.php') diff --git a/admin/user_list.php b/admin/user_list.php index 73c1537bb..f679d95ce 100644 --- a/admin/user_list.php +++ b/admin/user_list.php @@ -702,7 +702,7 @@ foreach ($visible_user_list as $local_user) 'CHECKED' => $checked, 'U_PROFILE' => $profile_url.$local_user['id'], 'U_PERM' => $perm_url.$local_user['id'], - 'USERNAME' => $local_user['username'] + 'USERNAME' => stripslashes($local_user['username']) .($local_user['id'] == $conf['guest_id'] ? '
['.l10n('is_the_guest').']' : '') .($local_user['id'] == $conf['default_user_id'] -- cgit v1.2.3