]> git.mjollnir.org Git - moodle.git/commitdiff
Strip slashes from admin search string (it's ok, it never gets near a database)
authormoodler <moodler>
Mon, 2 Oct 2006 13:35:28 +0000 (13:35 +0000)
committermoodler <moodler>
Mon, 2 Oct 2006 13:35:28 +0000 (13:35 +0000)
admin/search.php

index ea93dd661d92b4599efb15373298cfd07d267567..275e494a9a7a02a9fe070df35f91bcea64f03d68 100644 (file)
@@ -5,7 +5,7 @@
 require_once('../config.php');
 require_once($CFG->libdir.'/adminlib.php');
 
-$query = trim(required_param('query', PARAM_NOTAGS));  // Search string
+$query = trim(stripslashes_safe(required_param('query', PARAM_NOTAGS)));  // Search string
 
 $adminroot = admin_get_root();
 admin_externalpage_setup('search', $adminroot); // now hidden page