Show
Ignore:
Timestamp:
02/14/06 09:51:16 (3 years ago)
Author:
mbonetti
Message:

Some more fixes for possible sql injections

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/rss/admin/themes.php

    r1181 r1275  
    3636 
    3737    if (isset($_GET['theme']) && array_key_exists($_GET['theme'],$themes)) { 
    38         $sql = "update " . getTable('config') . " set value_ = '". $_GET['theme']."'" 
     38        $active_theme = sanitize($_GET['theme'], RSS_SANITIZER_SIMPLE_SQL |ÊRSS_SANITIZER_NO_SPACES); 
     39         
     40        $sql = "update " . getTable('config') . " set value_ = '$active_theme'" 
    3941               ." where key_='rss.output.theme'"; 
    4042        rss_query($sql); 
    41         $active_theme = $_GET['theme']; 
     43         
    4244        rss_invalidate_cache(); 
    4345    }    else {