FSN#33658: potentiële SQL-injections aangepast.

svn path=/Website/trunk/; revision=28184
This commit is contained in:
Maykel Geerdink
2016-02-16 10:08:56 +00:00
parent 617f964d60
commit 8454c1cb20

View File

@@ -93,12 +93,12 @@ function kpn_mandate_list(authparams, params)
+ " CASE" + " CASE"
+ " WHEN pk.prs_perslidkostenplaats_boeken = 1 " + " WHEN pk.prs_perslidkostenplaats_boeken = 1 "
+ " THEN " + safe.quoted_sql(L('lcl_yes')) + " THEN " + safe.quoted_sql(L('lcl_yes'))
+ " ELSE " + quoted_sql(L('lcl_no')) + " ELSE " + safe.quoted_sql(L('lcl_no'))
+ " END boeken, " + " END boeken, "
+ " CASE" + " CASE"
+ " WHEN pk.prs_perslidkostenplaats_inzage = 1 " + " WHEN pk.prs_perslidkostenplaats_inzage = 1 "
+ " THEN " + quoted_sql(L('lcl_yes')) + " THEN " + safe.quoted_sql(L('lcl_yes'))
+ " ELSE " + quoted_sql(L('lcl_no')) + " ELSE " + safe.quoted_sql(L('lcl_no'))
+ " END inzage, " + " END inzage, "
+ " k.prs_kostenplaats_key, " + " k.prs_kostenplaats_key, "
+ " k.prs_perslid_key verantwoordelijke_key, " + " k.prs_perslid_key verantwoordelijke_key, "