Merged 2.1.1-sportswgtn (SQL injection fix)

git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/cms/branches/2.1@58991 467b73ca-7a2a-4603-9d3b-597d59a354a9
This commit is contained in:
Sam Minnee 2008-07-23 06:30:40 +00:00
parent bbdc433dae
commit b76e16eb60
1 changed files with 2 additions and 2 deletions

View File

@ -163,7 +163,7 @@ class PageComment extends DataObject {
return "Comment by '". Convert::raw2xml($this->Name) . "' on " . $this->Parent()->Title;
}
function rss() {
$parentcheck = isset($_REQUEST['pageid']) ? "ParentID = {$_REQUEST['pageid']}" : "ParentID > 0";
$parentcheck = isset($_REQUEST['pageid']) ? "ParentID = " . (int) $_REQUEST['pageid'] : "ParentID > 0";
$comments = DataObject::get("PageComment", "$parentcheck AND IsSpam=0", "Created DESC", "", 10);
if(!isset($comments)) {
$comments = new DataObjectSet();
@ -187,4 +187,4 @@ class PageComment extends DataObject {
}
}
?>
?>