diff options
author | Mike Macgirvin <mike@macgirvin.com> | 2010-08-13 05:59:59 -0700 |
---|---|---|
committer | Mike Macgirvin <mike@macgirvin.com> | 2010-08-13 05:59:59 -0700 |
commit | 2ee1b00c9c17f9ae299376a84d8055b0308864bf (patch) | |
tree | c5c372a98c0dc1ab705c259aced238b9f8afde95 /mod | |
parent | e9a0d07f3a61a566236c31e74cc87a2d1985f911 (diff) | |
download | volse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.tar.gz volse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.tar.bz2 volse-hubzilla-2ee1b00c9c17f9ae299376a84d8055b0308864bf.zip |
missed escape on email receive
Diffstat (limited to 'mod')
-rw-r--r-- | mod/dfrn_notify.php | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/mod/dfrn_notify.php b/mod/dfrn_notify.php index 057dfcb42..03d96d27e 100644 --- a/mod/dfrn_notify.php +++ b/mod/dfrn_notify.php @@ -68,6 +68,7 @@ function dfrn_notify_post(&$a) { $msg['parent-uri'] = notags(unxmlify($base['in-reply-to'][0]['data'])); $msg['created'] = datetime_convert(notags(unxmlify('UTC','UTC',$base['sentdate'][0]['data']))); + dbesc_array($msg); $r = q("INSERT INTO `mail` (`" . implode("`, `", array_keys($msg)) . "`) VALUES ('" . implode("', '", array_values($msg)) . "')" ); |