From 6ceb14ef9243f0db96c2bb460fcb008d18fbfce7 Mon Sep 17 00:00:00 2001 From: Chris Morgan Date: Mon, 19 Jun 2006 15:40:53 +0000 Subject: [PATCH] Disable addslashes() in makeSafe() until more finely grained filtering can be implemented --- include/util.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/include/util.php b/include/util.php index 8a32d3c..ce8cd4b 100644 --- a/include/util.php +++ b/include/util.php @@ -2,7 +2,8 @@ function makeSafe($var) { - $var = trim(addslashes($var)); +/* Disable addslashes() until we can use more finely grained filtering on user input */ +/* $var = trim(addslashes($var)); */ return $var; }