Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/nextcloud/server.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorVincent Petry <pvince81@owncloud.com>2016-10-19 16:47:08 +0300
committerGitHub <noreply@github.com>2016-10-19 16:47:08 +0300
commited468d5c1ef91ccc91f30cb569dee2c668e43b7c (patch)
treeb8cd92d0b6b051f968b73f83c9270849c686bcd2 /lib
parenta9e8b7dd08b2cc39b5a914ec40dd65af02279f66 (diff)
parentab92c20d65b385e6df3aba90fade7a90028a3d22 (diff)
Merge pull request #26409 from owncloud/stable9-36d6f3ba8b7b7db8f4d8b2a70504fd184a30cc50
[stable9] Escape special characters (#25429)
Diffstat (limited to 'lib')
-rw-r--r--lib/private/group/database.php4
-rw-r--r--lib/private/repair/repairlegacystorages.php2
2 files changed, 3 insertions, 3 deletions
diff --git a/lib/private/group/database.php b/lib/private/group/database.php
index 9ea0bbb8242..503c29b99c0 100644
--- a/lib/private/group/database.php
+++ b/lib/private/group/database.php
@@ -294,7 +294,7 @@ class OC_Group_Database extends OC_Group_Backend {
$parameters = [$gid];
$searchLike = '';
if ($search !== '') {
- $parameters[] = '%' . $search . '%';
+ $parameters[] = '%' . $this->dbConn->escapeLikeParameter($search) . '%';
$searchLike = ' AND `uid` LIKE ?';
}
@@ -320,7 +320,7 @@ class OC_Group_Database extends OC_Group_Backend {
$parameters = [$gid];
$searchLike = '';
if ($search !== '') {
- $parameters[] = '%' . $search . '%';
+ $parameters[] = '%' . $this->dbConn->escapeLikeParameter($search) . '%';
$searchLike = ' AND `uid` LIKE ?';
}
diff --git a/lib/private/repair/repairlegacystorages.php b/lib/private/repair/repairlegacystorages.php
index ee189110a87..1442a3d1a7a 100644
--- a/lib/private/repair/repairlegacystorages.php
+++ b/lib/private/repair/repairlegacystorages.php
@@ -170,7 +170,7 @@ class RepairLegacyStorages extends BasicEmitter {
$sql = 'SELECT `id`, `numeric_id` FROM `*PREFIX*storages`'
. ' WHERE `id` LIKE ?'
. ' ORDER BY `id`';
- $result = $this->connection->executeQuery($sql, array($dataDirId . '%'));
+ $result = $this->connection->executeQuery($sql, array($this->connection->escapeLikeParameter($dataDirId) . '%'));
while ($row = $result->fetch()) {
$currentId = $row['id'];