From 3aceae9272691700457b2ae67521258c9186eaf0 Mon Sep 17 00:00:00 2001 From: "Paul S. Owen" Date: Thu, 1 Aug 2002 14:08:18 +0000 Subject: [PATCH] Non-slashed serialised data for admin logs... oops git-svn-id: file:///svn/phpbb/trunk@2800 89ea8834-ac86-4346-8a33-228a782c2dd0 --- phpBB/admin/pagestart.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/phpBB/admin/pagestart.php b/phpBB/admin/pagestart.php index b187a90294..63adc5be57 100644 --- a/phpBB/admin/pagestart.php +++ b/phpBB/admin/pagestart.php @@ -127,7 +127,7 @@ function add_admin_log() $arguments = func_get_args(); $action = array_shift($arguments); - $data = ( !sizeof($arguments) ) ? '' : serialize($arguments); + $data = ( !sizeof($arguments) ) ? '' : addslashes(serialize($arguments)); $sql = "INSERT INTO " . LOG_ADMIN_TABLE . " (user_id, log_ip, log_time, log_operation, log_data) VALUES (" . $userdata['user_id'] . ", '$user_ip', " . time() . ", '$action', '$data')"; @@ -164,7 +164,7 @@ function view_admin_log($limit = 0, $offset = 0, $limit_days = 0, $sort_by = 'l. if ( !empty($row['log_data']) ) { - $log_data_ary = unserialize($row['log_data']); + $log_data_ary = unserialize(stripslashes($row['log_data'])); foreach ( $log_data_ary as $log_data ) {