GIT.Harvie.CZ
/
mirrors
/
Kyberia-bloodline.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
reset_password fix
[mirrors/Kyberia-bloodline.git]
/
wwwroot
/
inc
/
eventz
/
banlist.inc
diff --git
a/wwwroot/inc/eventz/banlist.inc
b/wwwroot/inc/eventz/banlist.inc
index d817840602ddba28b6674bfb6a0c1646643e40f2..8f14448b3f372f1613fff245f7d489f98aa2ba90 100644
(file)
--- a/
wwwroot/inc/eventz/banlist.inc
+++ b/
wwwroot/inc/eventz/banlist.inc
@@
-8,7
+8,8
@@
if ($node['node_permission']!=('owner' || 'master' || 'op')) {
$error=$error_messages['EVENT_PERMISSION_ERROR'];
return false;
}
$error=$error_messages['EVENT_PERMISSION_ERROR'];
return false;
}
- $bans=explode(";",$_POST['bans']);
+ $bans = explode(";",$_POST['bans']); // XXX sqli?
+ $bans = array_map('db_escape_string', $bans);
$db->query("update node_access set node_permission='' where node_id=$node_id and node_permission='ban'");
foreach ($bans as $ban) {
$db->query("update node_access set node_permission='' where node_id=$node_id and node_permission='ban'");
foreach ($bans as $ban) {
This page took
0.124123 seconds
and
4
git commands to generate.