Migration to PDO database abstraction layer
[mirrors/Kyberia-bloodline.git] / wwwroot / inc / eventz / banlist.inc
index b806cb1c939b511f460801f88ca621a6ade24995..8f14448b3f372f1613fff245f7d489f98aa2ba90 100644 (file)
@@ -8,7 +8,8 @@ if ($node['node_permission']!=('owner' || 'master' || 'op')) {
 $error=$error_messages['EVENT_PERMISSION_ERROR'];
 return false;
 }
-               $bans=explode(";",$_POST['bans']); // XXX sqli?
+               $bans = explode(";",$_POST['bans']); // XXX sqli?
+               $bans = array_map('db_escape_string', $bans); 
 
                $db->query("update node_access set node_permission='' where node_id=$node_id and node_permission='ban'");
                foreach ($bans as $ban) {
This page took 0.126111 seconds and 4 git commands to generate.