PNBR#41284 SQL-injection voorkomen
svn path=/Website/trunk/; revision=34970
This commit is contained in:
@@ -115,17 +115,17 @@ else
|
||||
BLOCK_END();
|
||||
|
||||
BLOCK_START("mldInfo", L("lcl_faq_itemadm"));
|
||||
var sql= " SELECT 1, " + safe.quoted_sql(L("lcl_faq_level1")) + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 2, " + safe.quoted_sql(L("lcl_faq_level2")) + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 3, " + safe.quoted_sql(L("lcl_faq_level3")) + " FROM DUAL"
|
||||
var sql = " SELECT 1, " + safe.qL("lcl_faq_level1") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 2, " + safe.qL("lcl_faq_level2") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 3, " + safe.qL("lcl_faq_level3") + " FROM DUAL"
|
||||
FCLTselector("fac_faq_level", sql,
|
||||
{ initKey: level,
|
||||
label: L("lcl_faq_level")
|
||||
});
|
||||
|
||||
var displaySql = " SELECT 0, '" + L("lcl_faq_display_popup") + "' FROM DUAL UNION ALL "
|
||||
+ " SELECT 1, '" + L("lcl_faq_display_screen") + "' FROM DUAL UNION ALL "
|
||||
+ " SELECT 2, '" + L("lcl_faq_display_both_edit")+ "' FROM DUAL";
|
||||
var displaySql = " SELECT 0, " + safe.qL("lcl_faq_display_popup") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 1, " + safe.qL("lcl_faq_display_screen") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 2, " + safe.qL("lcl_faq_display_both_edit") + " FROM DUAL";
|
||||
|
||||
FCLTselector("fac_faq_displaymode",
|
||||
displaySql,
|
||||
|
||||
@@ -141,9 +141,9 @@ var canChange = canWriteFAQBOF || (canWriteFAQFOF && datum == null)
|
||||
BLOCK_START("mldInfo", L("lcl_faq_itemadm"));
|
||||
ROFIELDTR("fld", L("lcl_faq_level"), fac.getfaqleveltext(level));
|
||||
|
||||
var displaySql = " SELECT 0, '" + L("lcl_faq_display_popup") + "' FROM DUAL UNION ALL "
|
||||
+ " SELECT 1, '" + L("lcl_faq_display_screen") + "' FROM DUAL UNION ALL "
|
||||
+ " SELECT 2, '" + L("lcl_faq_display_both_show")+ "' FROM DUAL";
|
||||
var displaySql = " SELECT 0, " + safe.qL("lcl_faq_display_popup") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 1, " + safe.qL("lcl_faq_display_screen") + " FROM DUAL"
|
||||
+ " UNION ALL SELECT 2, " + safe.qL("lcl_faq_display_both_show") + " FROM DUAL";
|
||||
|
||||
FCLTselector("fld",
|
||||
displaySql,
|
||||
|
||||
Reference in New Issue
Block a user