added protection on insert in database
This commit is contained in:
@ -24,7 +24,7 @@ $dateFin = getpost("dateFin");
|
||||
if ($titre !== null and $libelle!== null and $dateDebut!== null and $dateFin !== null)
|
||||
{
|
||||
$db = new db();
|
||||
$query = "INSERT INTO liste_votations VALUES(0, '" . $titre . "', '" . $libelle . "', '0', '" . $dateDebut . "', '" . $dateFin . "')"; // clotûre
|
||||
$query = "INSERT INTO liste_votations VALUES(0, '" . $db->protect($titre) . "', '" . $db->protect($libelle) . "', '0', '" . $db->protect($dateDebut) . "', '" . $db->protect($dateFin) . "')"; // clotûre
|
||||
$db->query($query);
|
||||
$db->close();
|
||||
// TODO retour à l'index
|
||||
|
Reference in New Issue
Block a user