forked from science-ation/science-ation
escape some email usage incase of weird characters.
This commit is contained in:
parent
a83695bfe7
commit
e00e210690
@ -13,7 +13,7 @@ function auth_has_access($access="")
|
||||
}
|
||||
else
|
||||
{
|
||||
$q=mysql_query("SELECT access_admin, access_config, access_super FROM committees_members WHERE email='".$_SESSION['email']."' AND id='".$_SESSION['committee_member_id']."' AND deleted='N'");
|
||||
$q=mysql_query("SELECT access_admin, access_config, access_super FROM committees_members WHERE email='".mysql_escape_string($_SESSION['email'])."' AND id='".$_SESSION['committee_member_id']."' AND deleted='N'");
|
||||
|
||||
$r=mysql_fetch_object($q);
|
||||
$accesscache['admin']=$r->access_admin;
|
||||
|
@ -138,7 +138,7 @@
|
||||
if($_POST['action']=="login" && ( $_POST['email'] || $_SESSION['email']) )
|
||||
{
|
||||
if($_POST['email'])
|
||||
$_SESSION['email']=$_POST['email'];
|
||||
$_SESSION['email']=stripslashes(mysql_escape_string($_POST['email']));
|
||||
|
||||
echo "<form method=\"post\" action=\"register_participants.php\">";
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user