Version 1.1.2 ()
------------------------------------------------------------------------
+ * Fix showing SQL error message when an empty category is selected
+ for viewing. Fixes an issue reported by Samenspender that was
+ falsely declard as SQL injection. In fact, no invalid SQL
+ code can be injected. (garvinhicking)
+
* Better checks to see if the local PEAR inclusion is required
(garvinhicking)
$cat_sql_array[] = " (c.category_left " . ($invert ? " NOT " : "") . " BETWEEN " . implode(' AND ', serendipity_fetchCategoryRange($categoryid)) . ')';
}
}
+
+ if (count($cat_sql_array) < 1) {
+ return '';
+ }
return '(' . implode(($invert ? ' AND ' : ' OR '), $cat_sql_array) . ')';
}