Changeset 68 in subversion
- Timestamp:
- Oct 31, 2005 6:47:03 PM (8 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/roundcubemail/program/steps/addressbook/save.inc
r58 r68 35 35 continue; 36 36 37 $a_write_sql[] = sprintf("%s='%s'", $col, addslashes( $_POST[$fname]));37 $a_write_sql[] = sprintf("%s='%s'", $col, addslashes(strip_tags($_POST[$fname]))); 38 38 } 39 39 … … 104 104 105 105 $a_insert_cols[] = $col; 106 $a_insert_values[] = sprintf("'%s'", addslashes( $_POST[$fname]));106 $a_insert_values[] = sprintf("'%s'", addslashes(strip_tags($_POST[$fname]))); 107 107 } 108 108
Note: See TracChangeset
for help on using the changeset viewer.
