From f691bfe4d8e0016229096609a279df469dc37f99 Mon Sep 17 00:00:00 2001 From: Jannik Schönartz Date: Thu, 23 Nov 2017 14:16:38 +0100 Subject: [syslog] Added sql injection prevention --- modules-available/syslog/page.inc.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'modules-available/syslog') diff --git a/modules-available/syslog/page.inc.php b/modules-available/syslog/page.inc.php index 46b62d5d..e026107f 100644 --- a/modules-available/syslog/page.inc.php +++ b/modules-available/syslog/page.inc.php @@ -54,7 +54,9 @@ class Page_SysLog extends Page $whereClause .= ' WHERE '; else $whereClause .= ' AND '; - $whereClause .= "machineuuid='" . Request::get('machineuuid') . "'"; + + $muid = Request::get('machineuid', '', string); + $whereClause .= "machineuuid='" . $muid . "'"; } $today = date('d.m.Y'); $yesterday = date('d.m.Y', time() - 86400); -- cgit v1.2.3-55-g7522