aboutsummaryrefslogtreecommitdiffstats
path: root/mod
diff options
context:
space:
mode:
authorMike Macgirvin <mike@macgirvin.com>2010-08-13 05:59:59 -0700
committerMike Macgirvin <mike@macgirvin.com>2010-08-13 05:59:59 -0700
commit2ee1b00c9c17f9ae299376a84d8055b0308864bf (patch)
treec5c372a98c0dc1ab705c259aced238b9f8afde95 /mod
parente9a0d07f3a61a566236c31e74cc87a2d1985f911 (diff)
downloadvolse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.tar.gz
volse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.tar.bz2
volse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.zip
missed escape on email receive
Diffstat (limited to 'mod')
-rw-r--r--mod/dfrn_notify.php1
1 files changed, 1 insertions, 0 deletions
diff --git a/mod/dfrn_notify.php b/mod/dfrn_notify.php
index 057dfcb42..03d96d27e 100644
--- a/mod/dfrn_notify.php
+++ b/mod/dfrn_notify.php
@@ -68,6 +68,7 @@ function dfrn_notify_post(&$a) {
$msg['parent-uri'] = notags(unxmlify($base['in-reply-to'][0]['data']));
$msg['created'] = datetime_convert(notags(unxmlify('UTC','UTC',$base['sentdate'][0]['data'])));
+ dbesc_array($msg);
$r = q("INSERT INTO `mail` (`" . implode("`, `", array_keys($msg))
. "`) VALUES ('" . implode("', '", array_values($msg)) . "')" );