mirror of
https://github.com/silverstripe/silverstripe-mssql
synced 2024-10-22 08:05:53 +02:00
Merge pull request #1 from silverstripe-security/patch/1/SS-2017-008
[SS-2017-008] Fix SQL injection in search engine
This commit is contained in:
commit
aa21b10005
@ -197,6 +197,8 @@ class MSSQLDatabase extends SS_Database
|
|||||||
*/
|
*/
|
||||||
public function searchEngine($classesToSearch, $keywords, $start, $pageLength, $sortBy = "Relevance DESC", $extraFilter = "", $booleanSearch = false, $alternativeFileFilter = "", $invertedMatch = false)
|
public function searchEngine($classesToSearch, $keywords, $start, $pageLength, $sortBy = "Relevance DESC", $extraFilter = "", $booleanSearch = false, $alternativeFileFilter = "", $invertedMatch = false)
|
||||||
{
|
{
|
||||||
|
$start = (int)$start;
|
||||||
|
$pageLength = (int)$pageLength;
|
||||||
if (isset($objects)) {
|
if (isset($objects)) {
|
||||||
$results = new ArrayList($objects);
|
$results = new ArrayList($objects);
|
||||||
} else {
|
} else {
|
||||||
|
Loading…
Reference in New Issue
Block a user