Changeset 8615

Show
Ignore:
Timestamp:
01/14/10 22:08:33 (3 years ago)
Author:
p_lindheimer
Message:

Merged revisions 8613 via svnmerge from
http://svn.freepbx.org/modules/branches/2.6

........

r8613 | p_lindheimer | 2010-01-14 19:00:04 -0800 (Thu, 14 Jan 2010) | 1 line


sanatize cidnum to avoid potential SQL Injections

........

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • modules/branches/2.5

    • Property svnmerge-integrated changed from /modules/branches/2.4:1-5852,5908 /modules/branches/2.6:1-7080,7132,7158-7174,7177,7179-7186,7191-7202,7204-7226,7228-7250,7252-7273,7279-7286,7289-7292,7294-7295,7297-7312,7317-7331,7333-7340,7411,7413,7415-7417,7419-7420,7423-7434,7438-7439,7441-7442,7444-7446,7458-7469,7553,7609-7622,7697,7699-7701,7703-7707,7709-7710,7713-7722,7725-7731,7735-7736,7739-7740,7744-7751,7753-7759,7761-7774,7776-7787,7789-7791,7793-7795,7798,7806-7809,7811-7813,7816,7818-7821,7838,7858-7867,7871,7874-7882,7886-7893,7895-7896,7901,8589 to /modules/branches/2.4:1-5852,5908 /modules/branches/2.6:1-7080,7132,7158-7174,7177,7179-7186,7191-7202,7204-7226,7228-7250,7252-7273,7279-7286,7289-7292,7294-7295,7297-7312,7317-7331,7333-7340,7411,7413,7415-7417,7419-7420,7423-7434,7438-7439,7441-7442,7444-7446,7458-7469,7553,7609-7622,7697,7699-7701,7703-7707,7709-7710,7713-7722,7725-7731,7735-7736,7739-7740,7744-7751,7753-7759,7761-7774,7776-7787,7789-7791,7793-7795,7798,7806-7809,7811-7813,7816,7818-7821,7838,7858-7867,7871,7874-7882,7886-7893,7895-7896,7901,8589,8613
  • modules/branches/2.5/core/functions.inc.php

    r8344 r8615  
    24982498 
    24992499function core_did_get($extension="",$cidnum=""){ 
     2500  $cidnum = $db->escapeSimple($cidnum); 
    25002501  $sql = "SELECT * FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    25012502  return sql($sql,"getRow",DB_FETCHMODE_ASSOC); 
     
    25032504 
    25042505function core_did_del($extension,$cidnum){ 
     2506  $cidnum = $db->escapeSimple($cidnum); 
    25052507  $sql="DELETE FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    25062508  sql($sql);