Fixed security issues in file uploads.
[fa-stable.git] / inventory / includes / inventory_db.inc
index 34f7b3d94de0864d63602607d21ee224ba9adc96..79fda1196e44bc13f6811f186c7fc8082ab0d8c7 100644 (file)
@@ -27,7 +27,8 @@ include_once($path_to_root . "/inventory/includes/db/items_units_db.inc");
 
 function item_img_name($stock_id)
 {
-       return strtr($stock_id, "><\\/:|*?", '________');
+       $stock_id = strtr($stock_id, "><\\/:|*?", '________');
+       return clean_file_name($stock_id);
 }
 
-?>
\ No newline at end of file
+?>