From 1235bab5276f8c56ed6ba9cff46563c143c3e240 Mon Sep 17 00:00:00 2001 From: Eric Date: Wed, 18 Nov 2009 20:07:20 +0000 Subject: Escape all login and username characters in database Display correctly usernames (I hope not to have made mistakes) git-svn-id: http://piwigo.org/svn/trunk@4304 68402e56-0260-453c-a942-63ccdbb3a9ee --- admin/upload.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'admin/upload.php') diff --git a/admin/upload.php b/admin/upload.php index b36906778..94e526a35 100644 --- a/admin/upload.php +++ b/admin/upload.php @@ -177,7 +177,7 @@ while ( $row = mysql_fetch_assoc( $result ) ) (substr($row['file'], 0, 10)).'...' : $row['file'], 'PREVIEW_URL_IMG'=>$preview_url, 'UPLOAD_EMAIL'=>get_email_address_as_display_text($row['mail_address']), - 'UPLOAD_USERNAME'=>$row['username'] + 'UPLOAD_USERNAME'=>stripslashes($row['username']) ); // is there an existing associated thumnail ? -- cgit v1.2.3