5 Jan
2005
5 Jan
'05
6:10 p.m.
Hello, tony_lambregts(a)telusplanet.net wrote:
- "'$realname', '$email', NOW(), 0, 0)"); + "'$realname', '$email', NOW(), 0, 0, '$CVSrelease')");
Shouldn't one use "'".mysql_escape_string($username)."','" etc.? Or is it ensured elsewhere that no unwanted characters are in the string? ( ' is escaped in PHP, isn't it?) This is a not a security patch...
True, but shouldn't one try to be secure if one needs to touch such lines? Tobias