Changeset 8613

Show
Ignore:
Timestamp:
01/14/10 22:00:04 (3 years ago)
Author:
p_lindheimer
Message:

sanatize cidnum to avoid potential SQL Injections

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • modules/branches/2.6/core/functions.inc.php

    r8469 r8613  
    24752475 
    24762476function core_did_get($extension="",$cidnum=""){ 
     2477  $cidnum = $db->escapeSimple($cidnum); 
    24772478  $sql = "SELECT * FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    24782479  return sql($sql,"getRow",DB_FETCHMODE_ASSOC); 
     
    24802481 
    24812482function core_did_del($extension,$cidnum){ 
     2483  $cidnum = $db->escapeSimple($cidnum); 
    24822484  $sql="DELETE FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    24832485  sql($sql);