The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#6
|
|||
|
|||
![]()
Of course it does. This is really improper use of MySQL... And I really think that before writing your applications, you should read the tutorial and security tips.
However, I appreciate you trying to be creative, so there you go: 1. In MySQL queries, always enclose values into single quotes ('). That is how the script knows, where the string starts and where it ends. 2. In MySQL queries, when there is user input that cannot be validated, always use addslashes function. Therefore, the correct query would be: Code:
$DB_site->query(" UPDATE " . TABLE_PREFIX . "attachment SET postid = $post[postid], posthash = '', caption = '" . addslashes($attach[caption]) . "' WHERE posthash = '" . addslashes($post['posthash']) . "' AND userid = $bbuserinfo[userid] "); ![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|