Use query_parameters() in SQL select, update and delete statements to protect against

sql injection attacks
This commit is contained in:
Chris Morgan
2006-06-27 19:16:27 +00:00
committed by WineHQ
parent e6458694f4
commit e3f9e5371a
46 changed files with 602 additions and 484 deletions

View File

@@ -40,8 +40,7 @@ if(!$oDistribution->iDistributionId)
apidb_header("View Distributions");
//get available Distributions
$sQuery = "SELECT distributionId FROM distributions ORDER BY name, distributionId;";
$hResult = query_appdb($sQuery);
$hResult = query_parameters("SELECT distributionId FROM distributions ORDER BY name, distributionId;");
// show Distribution list
echo html_frame_start("","90%","",0);