From 41fe69917c8fc7fd75785eb623897868dccafa81 Mon Sep 17 00:00:00 2001 From: Eric Date: Wed, 18 Nov 2009 21:14:58 +0000 Subject: Forgotten Comments author name to be escaped and correctly displayed git-svn-id: http://piwigo.org/svn/trunk@4305 68402e56-0260-453c-a942-63ccdbb3a9ee --- include/functions_comment.inc.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'include') diff --git a/include/functions_comment.inc.php b/include/functions_comment.inc.php index aff7b9a35..3ac005223 100644 --- a/include/functions_comment.inc.php +++ b/include/functions_comment.inc.php @@ -156,9 +156,9 @@ SELECT id FROM '.COMMENTS_TABLE.' INSERT INTO '.COMMENTS_TABLE.' (author, author_id, content, date, validated, validation_date, image_id) VALUES ( - "'.$comm['author'].'", + "'.addslashes($comm['author']).'", '.$comm['author_id'].', - "'.$comm['content'].'", + "'.addslashes($comm['content']).'", NOW(), "'.($comment_action=='validate' ? 'true':'false').'", '.($comment_action=='validate' ? 'NOW()':'NULL').', -- cgit v1.2.3