added check_login() to check passed credentials, [set_pasword] should work now
[mirrors/Kyberia-bloodline.git] / wwwroot / inc / eventz / banlist.inc
index d817840602ddba28b6674bfb6a0c1646643e40f2..3f08d4d01cf9e0bd5bc26413e8ca025fb47ba620 100644 (file)
@@ -8,7 +8,8 @@ if ($node['node_permission']!=('owner' || 'master' || 'op')) {
 $error=$error_messages['EVENT_PERMISSION_ERROR'];
 return false;
 }
-               $bans=explode(";",$_POST['bans']);
+               $bans = explode(";",$_POST['bans']); // XXX sqli?
+               $bans = array_map('mysql_real_escape_string', $bans); 
 
                $db->query("update node_access set node_permission='' where node_id=$node_id and node_permission='ban'");
                foreach ($bans as $ban) {
This page took 0.095497 seconds and 4 git commands to generate.