Escape input in searchForApplication()

This commit is contained in:
Alexander Nicolaysen Sørnes
2008-06-18 00:19:28 +02:00
committed by Chris Morgan
parent 88c098c83f
commit e646626c4a

View File

@@ -462,12 +462,12 @@ function searchForApplication($search_words)
FROM appFamily
WHERE appName != 'NONAME'
AND appFamily.state = 'accepted'
AND (appName LIKE '%" . $search_words . "%'
OR keywords LIKE '%" . $search_words . "%'";
AND (appName LIKE '%?%'
OR keywords LIKE '%?%'";
$sQuery.=" ) ORDER BY appName";
$hResult = query_appdb($sQuery);
$hResult = query_parameters($sQuery, $search_words, $search_words);
return $hResult;
}