From 4e5bd4718309e86bce53ef590d37c662ae8daade Mon Sep 17 00:00:00 2001 From: Christian Boltz Date: Sun, 15 Jan 2012 11:22:01 +0000 Subject: [PATCH] functions.inc.php: - pacrypt(): escape_string() $salt for mysql_encrypt to be on the safe side git-svn-id: https://svn.code.sf.net/p/postfixadmin/code/trunk@1332 a1433add-5e2c-0410-b055-b7f2511e0802 --- functions.inc.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/functions.inc.php b/functions.inc.php index fb0e33f5..c172612c 100644 --- a/functions.inc.php +++ b/functions.inc.php @@ -1101,7 +1101,7 @@ function pacrypt ($pw, $pw_db="") { elseif ($CONF['encrypt'] == 'mysql_encrypt') { $pw = escape_string($pw); if ($pw_db!="") { - $salt=substr($pw_db,0,2); + $salt=escape_string(substr($pw_db,0,2)); $res=db_query("SELECT ENCRYPT('".$pw."','".$salt."');"); } else { $res=db_query("SELECT ENCRYPT('".$pw."');");