Prevent from address book XSS

release-0.6
thomascube 19 years ago
parent 7cc38e0beb
commit 9db57c57fe

@ -34,7 +34,7 @@ if ($_POST['_cid'])
if (!isset($_POST[$fname]))
continue;
$a_write_sql[] = sprintf("%s='%s'", $col, addslashes($_POST[$fname]));
$a_write_sql[] = sprintf("%s='%s'", $col, addslashes(strip_tags($_POST[$fname])));
}
if (sizeof($a_write_sql))
@ -103,7 +103,7 @@ else
continue;
$a_insert_cols[] = $col;
$a_insert_values[] = sprintf("'%s'", addslashes($_POST[$fname]));
$a_insert_values[] = sprintf("'%s'", addslashes(strip_tags($_POST[$fname])));
}
if (sizeof($a_insert_cols))

Loading…
Cancel
Save