Changeset 8616

Show
Ignore:
Timestamp:
01/14/10 21:11:12 (2 years ago)
Author:
p_lindheimer
Message:

Merged revisions 8615 via svnmerge from
http://svn.freepbx.org/modules/branches/2.5

................

r8615 | p_lindheimer | 2010-01-14 19:08:33 -0800 (Thu, 14 Jan 2010) | 9 lines


Merged revisions 8613 via svnmerge from
http://svn.freepbx.org/modules/branches/2.6


........

r8613 | p_lindheimer | 2010-01-14 19:00:04 -0800 (Thu, 14 Jan 2010) | 1 line


sanatize cidnum to avoid potential SQL Injections

........

................

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • modules/branches/2.4

    • Property svnmerge-integrated changed from /modules/branches/2.3:1-5233,5245,5333,5336 /modules/branches/2.5:1-5852,5880,5930,5995,6016-6017,6030-6031,6142,6218,6291,6361,6363,6413-6414,6422,6428-6430,6442-6443,6557,6710,6714-6715,6969-6970,6984,7248,7281,7858-7859,7875,7878,7886,7890 to /modules/branches/2.3:1-5233,5245,5333,5336 /modules/branches/2.5:1-5852,5880,5930,5995,6016-6017,6030-6031,6142,6218,6291,6361,6363,6413-6414,6422,6428-6430,6442-6443,6557,6710,6714-6715,6969-6970,6984,7248,7281,7858-7859,7875,7878,7886,7890,8615
  • modules/branches/2.4/core/functions.inc.php

    r7892 r8616  
    16061606 
    16071607function core_did_get($extension="",$cidnum=""){ 
     1608  $cidnum = $db->escapeSimple($cidnum); 
    16081609  $sql = "SELECT * FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    16091610  return sql($sql,"getRow",DB_FETCHMODE_ASSOC); 
     
    16111612 
    16121613function core_did_del($extension,$cidnum){ 
     1614  $cidnum = $db->escapeSimple($cidnum); 
    16131615  $sql="DELETE FROM incoming WHERE cidnum = \"$cidnum\" AND extension = \"$extension\""; 
    16141616  sql($sql);