From dd0171c7265728f7894359f1519a0d68d88afc20 Mon Sep 17 00:00:00 2001 From: Tobias Reich Date: Fri, 24 Jan 2014 16:53:22 +0100 Subject: [PATCH] Avoid sql injection on edge cases --- php/modules/db.php | 3 +++ 1 file changed, 3 insertions(+) diff --git a/php/modules/db.php b/php/modules/db.php index 792e2d6..4213e15 100755 --- a/php/modules/db.php +++ b/php/modules/db.php @@ -25,6 +25,9 @@ function dbConnect() { if (!$database->query("SELECT * FROM lychee_photos, lychee_albums, lychee_settings;")) if (!createTables($database)) exit('Error: Could not create tables!'); + // Avoid sql injection + $database->set_charset('GBK'); + return $database; }