FCLT#54933 Filename injection voorkomen
svn path=/Website/branches/v2018.1/; revision=39368
This commit is contained in:
@@ -34,7 +34,7 @@ if (cad_tek_key > 0)
|
||||
{
|
||||
if (file != "")
|
||||
sql = "UPDATE cad_tekening"
|
||||
+ " SET cad_tekening_filenaam = " + safe.quoted_sql(file)
|
||||
+ " SET cad_tekening_filenaam = " + safe.quoted_sql(safe.filename(file))
|
||||
+ " WHERE cad_tekening_key = " + cad_tek_key;
|
||||
else
|
||||
sql = "DELETE FROM cad_tekening"
|
||||
|
||||
Reference in New Issue
Block a user