Security issue: Database::escape_string function added

skala
Julio Montoya 16 years ago
parent c250e4765b
commit 2e07249f31
  1. 9
      main/calendar/agenda.inc.php

@ -1529,12 +1529,9 @@ function get_agenda_item($id)
$t_agenda_repeat = Database::get_course_table(TABLE_AGENDA_REPEAT); $t_agenda_repeat = Database::get_course_table(TABLE_AGENDA_REPEAT);
$id=Database::escape_string($id); $id=Database::escape_string($id);
$item = array(); $item = array();
if(empty($id)) if(empty($id)) {
{ $id=intval(Database::escape_string(($_GET['id'])));
$id=(int)addslashes($_GET['id']); } else {
}
else
{
$id = (int) $id; $id = (int) $id;
} }
if(empty($id)){return $item;} if(empty($id)){return $item;}

Loading…
Cancel
Save