Security update merged from 2.1.
[fa-stable.git] / admin / print_profiles.php
index 99ef82e1d5144c6e1e9645f616751c8974708177..02e3701c55a9a2af8b13a55c1f5f53a16614ca96 100644 (file)
@@ -77,7 +77,7 @@ function check_delete($name)
 {
 // check if selected profile is used by any user
        if ($name=='') return 0; // cannot delete system default profile
-       $sql = "SELECT * FROM ".TB_PREF."users WHERE print_profile='$name'";
+       $sql = "SELECT * FROM ".TB_PREF."users WHERE print_profile=".db_escape($name);
        $res = db_query($sql,'cannot check printing profile usage');
        return db_num_rows($res);
 }