From cf6bea5727748ba9c970c8c159259d99d5e864f7 Mon Sep 17 00:00:00 2001 From: james Date: Thu, 22 Oct 2009 20:40:35 +0000 Subject: [PATCH] stripslashes --- admin/fundraising_campaigns.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/admin/fundraising_campaigns.php b/admin/fundraising_campaigns.php index d90b336..7eac82d 100644 --- a/admin/fundraising_campaigns.php +++ b/admin/fundraising_campaigns.php @@ -505,7 +505,7 @@ function save_campaign_info(){ if(!$_GET['id']) { $query = "INSERT INTO fundraising_campaigns (name,fiscalyear) VALUES ( - '".mysql_real_escape_string($_POST['name'])."','{$config['FISCALYEAR']}')"; + '".mysql_real_escape_string(stripslashes($_POST['name']))."','{$config['FISCALYEAR']}')"; mysql_query($query); $id = mysql_insert_id(); happy_("Appeal Created"); @@ -514,7 +514,7 @@ function save_campaign_info(){ happy_("Appeal Saved"); } mysql_query("UPDATE fundraising_campaigns SET - name='".mysql_real_escape_string($_POST['name'])."', + name='".mysql_real_escape_string(stripslashes($_POST['name']))."', `type`='".mysql_real_escape_string($_POST['type'])."', startdate='".mysql_real_escape_string($startdate)."', followupdate='".mysql_real_escape_string($_POST['followupdate'])."',