authenticate_user: properly escape input
This commit is contained in:
parent
f574fec6a6
commit
2d969845f9
|
@ -1741,6 +1741,7 @@
|
||||||
|
|
||||||
$pwd_hash1 = encrypt_password($password);
|
$pwd_hash1 = encrypt_password($password);
|
||||||
$pwd_hash2 = encrypt_password($password, $login);
|
$pwd_hash2 = encrypt_password($password, $login);
|
||||||
|
$login = db_escape_string($login);
|
||||||
|
|
||||||
if (defined('ALLOW_REMOTE_USER_AUTH') && ALLOW_REMOTE_USER_AUTH
|
if (defined('ALLOW_REMOTE_USER_AUTH') && ALLOW_REMOTE_USER_AUTH
|
||||||
&& $_SERVER["REMOTE_USER"] && $login != "admin") {
|
&& $_SERVER["REMOTE_USER"] && $login != "admin") {
|
||||||
|
|
Loading…
Reference in New Issue