Escape input in searchForApplication()
This commit is contained in:
committed by
Chris Morgan
parent
88c098c83f
commit
e646626c4a
@@ -462,12 +462,12 @@ function searchForApplication($search_words)
|
|||||||
FROM appFamily
|
FROM appFamily
|
||||||
WHERE appName != 'NONAME'
|
WHERE appName != 'NONAME'
|
||||||
AND appFamily.state = 'accepted'
|
AND appFamily.state = 'accepted'
|
||||||
AND (appName LIKE '%" . $search_words . "%'
|
AND (appName LIKE '%?%'
|
||||||
OR keywords LIKE '%" . $search_words . "%'";
|
OR keywords LIKE '%?%'";
|
||||||
|
|
||||||
$sQuery.=" ) ORDER BY appName";
|
$sQuery.=" ) ORDER BY appName";
|
||||||
|
|
||||||
$hResult = query_appdb($sQuery);
|
$hResult = query_parameters($sQuery, $search_words, $search_words);
|
||||||
return $hResult;
|
return $hResult;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user