escaping database inputs

Created on 21 March 2006, about 19 years ago
Updated 11 June 2025, 2 days ago

When trying to upload a file that had an apostrophy in the author's name, an SQL error occured. It seems values aren't being escaped before being entered into the database, though keys are. I'd have thought it should be the other way around?

I've attached a patch which adds this, unless there is some reason why values shouldn't be checked?

πŸ› Bug report
Status

Closed: outdated

Version

1.0

Component

Code

Created by

πŸ‡¬πŸ‡§United Kingdom geodaniel

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

  • πŸ‡ΊπŸ‡ΈUnited States bluegeek9

    Thank you for your contributions to this issue. As Drupal 4 has reached its End of Life and is no longer supported, we are closing this issue. We encourage you to upgrade to a supported version of Drupal.

Production build 0.71.5 2024