From c3693e94fbbdefb9f84f633fc0efadfd2324bbf0 Mon Sep 17 00:00:00 2001 From: Jannik Schönartz Date: Thu, 23 Nov 2017 15:06:38 +0100 Subject: [syslog] Fixed sql injection prevention --- modules-available/syslog/page.inc.php | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) (limited to 'modules-available/syslog') diff --git a/modules-available/syslog/page.inc.php b/modules-available/syslog/page.inc.php index e026107f..927a3adf 100644 --- a/modules-available/syslog/page.inc.php +++ b/modules-available/syslog/page.inc.php @@ -55,8 +55,7 @@ class Page_SysLog extends Page else $whereClause .= ' AND '; - $muid = Request::get('machineuid', '', string); - $whereClause .= "machineuuid='" . $muid . "'"; + $whereClause .= "machineuuid='" . preg_replace('/[^0-9a-zA-Z\-]/', '', Request::get('machineuuid', '', 'string')) . "'"; } $today = date('d.m.Y'); $yesterday = date('d.m.Y', time() - 86400); -- cgit v1.2.3-55-g7522