Security update merged from 2.1.
[fa-stable.git] / includes / db / connect_db.inc
index f91d70235fe0bb53eec1dae5182b13030f770dc2..d6b6e71ab04f83a35c554b08a2d146de6618997c 100644 (file)
@@ -100,6 +100,7 @@ function db_num_fields ($result)
 
 function db_escape($value = "", $nullify = false)
 {
+       $value = @html_entity_decode($value, ENT_QUOTES, $_SESSION['language']->encoding);
        $value = @htmlspecialchars($value, ENT_QUOTES, $_SESSION['language']->encoding);
 
        //reset default if second parameter is skipped