From 4cf90f14615491d94871236967e3f1ebab70711b Mon Sep 17 00:00:00 2001 From: Janusz Dobrowolski Date: Mon, 19 Oct 2009 06:33:58 +0000 Subject: [PATCH] Fixed double escaping gl account name on add/update. --- CHANGELOG.txt | 6 +++++- gl/includes/db/gl_db_accounts.inc | 2 -- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.txt b/CHANGELOG.txt index 647dad6..a78c2d1 100644 --- a/CHANGELOG.txt +++ b/CHANGELOG.txt @@ -19,9 +19,13 @@ Legend: ! -> Note $ -> Affected files +18-Oct-2009 Joe Hunt +# Fixed double escaping gl account name on add/update. +$ /gl/includes/db/gl_db_accounts.inc + ------------------------------- Release 2.1.7 ---------------------------------- ! Seccurity release 2.1.7. We strongly encourage to update to this release. -16-ock-2009 Joe Hunt +16-Oct-2009 Joe Hunt $ config.php 15-Oct-2009 Joe Hunt diff --git a/gl/includes/db/gl_db_accounts.inc b/gl/includes/db/gl_db_accounts.inc index 7b1cb63..2eed9ad 100644 --- a/gl/includes/db/gl_db_accounts.inc +++ b/gl/includes/db/gl_db_accounts.inc @@ -11,7 +11,6 @@ ***********************************************************************/ function add_gl_account($account_code, $account_name, $account_type, $account_code2) { - $account_name = db_escape($account_name); $sql = "INSERT INTO ".TB_PREF."chart_master (account_code, account_code2, account_name, account_type) VALUES (".db_escape($account_code).", ".db_escape($account_code2).", " .db_escape($account_name).", ".db_escape($account_type).")"; @@ -21,7 +20,6 @@ function add_gl_account($account_code, $account_name, $account_type, $account_co function update_gl_account($account_code, $account_name, $account_type, $account_code2) { - $account_name = db_escape($account_name); $sql = "UPDATE ".TB_PREF."chart_master SET account_name=".db_escape($account_name) .",account_type=".db_escape($account_type).", account_code2=".db_escape($account_code2) ." WHERE account_code = ".db_escape($account_code); -- 2.30.2