From fb21d51aa219f96d2dc3780d352411df93450a34 Mon Sep 17 00:00:00 2001 From: plegall Date: Mon, 25 Jan 2010 15:18:49 +0000 Subject: bug 1391 fixed: prevent from SQL injection git-svn-id: http://piwigo.org/svn/branches/2.0@4742 68402e56-0260-453c-a942-63ccdbb3a9ee --- feed.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/feed.php b/feed.php index bbd4956f5..4da7fb4fe 100644 --- a/feed.php +++ b/feed.php @@ -63,6 +63,8 @@ function ts_to_iso8601($ts) // | initialization | // +-----------------------------------------------------------------------+ +check_input_parameter('feed', $_GET['feed'], false, '/^[0-9a-z]{50}$/i'); + $feed_id= isset($_GET['feed']) ? $_GET['feed'] : ''; $image_only=isset($_GET['image_only']); -- cgit v1.2.3