- use preg_replace() instead of sanitizeString()

This commit is contained in:
steinm 2011-12-01 21:36:18 +00:00
parent 599995edbc
commit a802ad604e

View File

@ -47,7 +47,7 @@ if ($document->getAccessMode($user) < M_READWRITE) {
$name = sanitizeString($_POST["name"]); $name = sanitizeString($_POST["name"]);
$comment = sanitizeString($_POST["comment"]); $comment = sanitizeString($_POST["comment"]);
$keywords = sanitizeString($_POST["keywords"]); $keywords = sanitizeString($_POST["keywords"]);
$categories = sanitizeString($_POST["categoryidform1"]); $categories = preg_replace('/[^0-9,]+/', '', $_POST["categoryidform1"]);
$sequence = $_POST["sequence"]; $sequence = $_POST["sequence"];
if (!is_numeric($sequence)) { if (!is_numeric($sequence)) {
$sequence="keep"; $sequence="keep";