- call qstr() for name and comment

This commit is contained in:
steinm 2011-12-03 16:20:05 +00:00
parent d332984803
commit 6e0df090c6

View File

@ -127,7 +127,7 @@ class LetoDMS_Core_Folder {
function setName($newName) { /* {{{ */
$db = $this->_dms->getDB();
$queryStr = "UPDATE tblFolders SET name = '" . $newName . "' WHERE id = ". $this->_id;
$queryStr = "UPDATE tblFolders SET name = " . $db->qstr($newName) . " WHERE id = ". $this->_id;
if (!$db->getResult($queryStr))
return false;
@ -141,7 +141,7 @@ class LetoDMS_Core_Folder {
function setComment($newComment) { /* {{{ */
$db = $this->_dms->getDB();
$queryStr = "UPDATE tblFolders SET comment = '" . $newComment . "' WHERE id = ". $this->_id;
$queryStr = "UPDATE tblFolders SET comment = " . $db->qstr($newComment) . " WHERE id = ". $this->_id;
if (!$db->getResult($queryStr))
return false;