Menu

#2 Escape all entries and edits into the db

open
nobody
None
7
2002-02-17
2002-02-17
No

There are some profile edits (namely team) that don't
escape all the necessary fields before trying to
insert them into the db. This has to get fixed!

Discussion

  • Joyce Park

    Joyce Park - 2002-02-23

    Logged In: YES
    user_id=198484

    On Webpipe we have magicquotes on. Shouldn't that take
    care of it?

     
  • Alexander Selkirk

    Logged In: YES
    user_id=305120

    Well it doesn't right now - any quotes in there mess up the
    insert query on the various profile edit pages (useredit,
    projectedit, teamedit, etc...)

     

Log in to post a comment.