1
0
Fork 0
mirror of https://github.com/processone/ejabberd synced 2025-10-03 17:59:31 +02:00

security bugfix

SVN Revision: 718
This commit is contained in:
Christophe Romain 2007-02-02 10:58:40 +00:00
parent fcc4adcde5
commit 85a7a306ff

View file

@ -821,12 +821,13 @@ record_to_string(#roster{us = {User, _Server},
in -> "I"; in -> "I";
none -> "N" none -> "N"
end, end,
SAskMessage = ejabberd_odbc:escape(AskMessage),
["'", Username, "'," ["'", Username, "',"
"'", SJID, "'," "'", SJID, "',"
"'", Nick, "'," "'", Nick, "',"
"'", SSubscription, "'," "'", SSubscription, "',"
"'", SAsk, "'," "'", SAsk, "',"
"'", AskMessage, "'," "'", SAskMessage, "',"
"'N', '', 'item'"]. "'N', '', 'item'"].
groups_to_string(#roster{us = {User, _Server}, groups_to_string(#roster{us = {User, _Server},