diff --git a/todo.txt b/todo.txt index 5dad5f3..2a374ba 100644 --- a/todo.txt +++ b/todo.txt @@ -4,6 +4,11 @@ default design noch bearbeiten alix6: +magic quote support einstellen, +wenn magic, dann unquote in savesql +beim rausholen: neu: getsql oder killhtml, was getsql nutzt +getsql = wrapper falls in zukunft was geändert werden muss + noscript.css (special wie import.css) captcha-vorschau diff --git a/www/includes/functions.php b/www/includes/functions.php index d88277f..d40945e 100644 --- a/www/includes/functions.php +++ b/www/includes/functions.php @@ -1184,7 +1184,7 @@ function savesql ( $TEXT ) global $db; if ( !is_numeric ( $TEXT ) ) { - $TEXT = mysql_real_escape_string ( unquote ( $TEXT ), $db ); + $TEXT = mysql_real_escape_string ( addslashes ( unquote ( $TEXT ) ), $db ); } return $TEXT; }