diff --git a/admin/fundraising_campaigns.php b/admin/fundraising_campaigns.php index d90b336..7eac82d 100644 --- a/admin/fundraising_campaigns.php +++ b/admin/fundraising_campaigns.php @@ -505,7 +505,7 @@ function save_campaign_info(){ if(!$_GET['id']) { $query = "INSERT INTO fundraising_campaigns (name,fiscalyear) VALUES ( - '".mysql_real_escape_string($_POST['name'])."','{$config['FISCALYEAR']}')"; + '".mysql_real_escape_string(stripslashes($_POST['name']))."','{$config['FISCALYEAR']}')"; mysql_query($query); $id = mysql_insert_id(); happy_("Appeal Created"); @@ -514,7 +514,7 @@ function save_campaign_info(){ happy_("Appeal Saved"); } mysql_query("UPDATE fundraising_campaigns SET - name='".mysql_real_escape_string($_POST['name'])."', + name='".mysql_real_escape_string(stripslashes($_POST['name']))."', `type`='".mysql_real_escape_string($_POST['type'])."', startdate='".mysql_real_escape_string($startdate)."', followupdate='".mysql_real_escape_string($_POST['followupdate'])."',