MySQL error on submitting a quote with a ' in it
Brought to you by:
osqdb
In add.inc.php the system is not currently cleaning
the submitted entry correctly before inserting it
into the database
/* Filter 'bad' characters from quote */
$newquote = htmlspecialchars("$newquote");
$newquote = nl2br($newquote);
$comment = htmlspecialchars("$comment");
Here the quote is cleaned, but your not taking care
of single quotes.
Should be
/* Filter 'bad' characters from quote */
$newquote = addslashes("$newquote");
$newquote = htmlspecialchars("$newquote");
$newquote = nl2br($newquote);
$comment = addslashes("$comment");
$comment = htmlspecialchars("$comment");
Should also take care of preping the comments too.
Logged In: NO
Thanks, theres actually a few places this should be added,
i'll take a look at this tonight
Logged In: NO
Just the first place I saw it and had a problem with it,
I'm sure its possibly missing in other places as well.
Logged In: NO
Any updates?
Sorta wanting to go live, but didn't have time to browse
over everything.