fix proper escaping of label titles (closes #255)
This commit is contained in:
parent
4e332844b4
commit
7a13338b4c
|
@ -450,7 +450,8 @@
|
||||||
$ids = split(",", db_escape_string($_REQUEST["ids"]));
|
$ids = split(",", db_escape_string($_REQUEST["ids"]));
|
||||||
$label_id = db_escape_string($_REQUEST["lid"]);
|
$label_id = db_escape_string($_REQUEST["lid"]);
|
||||||
|
|
||||||
$label = label_find_caption($link, $label_id, $_SESSION["uid"]);
|
$label = db_escape_string(label_find_caption($link, $label_id,
|
||||||
|
$_SESSION["uid"]));
|
||||||
|
|
||||||
print "<rpc-reply>";
|
print "<rpc-reply>";
|
||||||
print "<info-for-headlines>";
|
print "<info-for-headlines>";
|
||||||
|
@ -485,7 +486,8 @@
|
||||||
$ids = split(",", db_escape_string($_REQUEST["ids"]));
|
$ids = split(",", db_escape_string($_REQUEST["ids"]));
|
||||||
$label_id = db_escape_string($_REQUEST["lid"]);
|
$label_id = db_escape_string($_REQUEST["lid"]);
|
||||||
|
|
||||||
$label = label_find_caption($link, $label_id, $_SESSION["uid"]);
|
$label = db_escape_string(label_find_caption($link, $label_id,
|
||||||
|
$_SESSION["uid"]));
|
||||||
|
|
||||||
print "<rpc-reply>";
|
print "<rpc-reply>";
|
||||||
|
|
||||||
|
|
|
@ -61,6 +61,8 @@
|
||||||
|
|
||||||
/* Update filters that reference label being renamed */
|
/* Update filters that reference label being renamed */
|
||||||
|
|
||||||
|
$old_caption = db_escape_string($old_caption);
|
||||||
|
|
||||||
db_query($link, "UPDATE ttrss_filters SET
|
db_query($link, "UPDATE ttrss_filters SET
|
||||||
action_param = '$caption' WHERE action_param = '$old_caption'
|
action_param = '$caption' WHERE action_param = '$old_caption'
|
||||||
AND action_id = 7
|
AND action_id = 7
|
||||||
|
|
Loading…
Reference in New Issue