Skip to content

Commit baf5dda

Browse files
committed
fix escaping in sql query
1 parent 9ec3045 commit baf5dda

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

interface/lib/classes/tools_sites.inc.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -156,7 +156,7 @@ function getDomainModuleDomains($not_used_in_table = null, $selected_domain = nu
156156
$field = "domain";
157157
$select = $field;
158158
}
159-
$sql .= " domain NOT IN (SELECT $select FROM $not_used_in_table WHERE $field != '$selected_domain') AND";
159+
$sql .= " domain NOT IN (SELECT $select FROM ?? WHERE $field != ?) AND";
160160
}
161161
if ($_SESSION["s"]["user"]["typ"] == 'admin') {
162162
$sql .= " 1";
@@ -165,7 +165,7 @@ function getDomainModuleDomains($not_used_in_table = null, $selected_domain = nu
165165
$sql .= " sys_groupid IN (".$groups.")";
166166
}
167167
$sql .= " ORDER BY domain";
168-
return $app->db->queryAllRecords($sql);
168+
return $app->db->queryAllRecords($sql, $not_used_in_table, $selected_domain);
169169
}
170170

171171
function checkDomainModuleDomain($domain_id) {

0 commit comments

Comments
 (0)