Fixed: better input validation, thanks to Niels Teusink for pointing this one out

git-svn-id: file:///svn/phpbb/branches/phpBB-2_0_0@4680 89ea8834-ac86-4346-8a33-228a782c2dd0
This commit is contained in:
Ludovic Arnaud 2003-11-22 22:36:13 +00:00
parent 05827b8195
commit f51bf61478

View file

@ -682,7 +682,8 @@ else if ( $search_keywords != '' || $search_author != '' || $search_id )
} }
else else
{ {
if ( intval($search_id) ) $search_id = intval($search_id);
if ( $search_id )
{ {
$sql = "SELECT search_array $sql = "SELECT search_array
FROM " . SEARCH_TABLE . " FROM " . SEARCH_TABLE . "