escape some email usage incase of weird characters.

This commit is contained in:
james 2007-10-25 15:12:20 +00:00
parent a83695bfe7
commit e00e210690
2 changed files with 2 additions and 2 deletions

View File

@ -13,7 +13,7 @@ function auth_has_access($access="")
}
else
{
$q=mysql_query("SELECT access_admin, access_config, access_super FROM committees_members WHERE email='".$_SESSION['email']."' AND id='".$_SESSION['committee_member_id']."' AND deleted='N'");
$q=mysql_query("SELECT access_admin, access_config, access_super FROM committees_members WHERE email='".mysql_escape_string($_SESSION['email'])."' AND id='".$_SESSION['committee_member_id']."' AND deleted='N'");
$r=mysql_fetch_object($q);
$accesscache['admin']=$r->access_admin;

View File

@ -138,7 +138,7 @@
if($_POST['action']=="login" && ( $_POST['email'] || $_SESSION['email']) )
{
if($_POST['email'])
$_SESSION['email']=$_POST['email'];
$_SESSION['email']=stripslashes(mysql_escape_string($_POST['email']));
echo "<form method=\"post\" action=\"register_participants.php\">";