interface/lib/classes/db_mysql.inc.php
@@ -135,9 +135,10 @@ $string_orig = $string; //echo $string; $chars = array(';', '#', '/*', '*/', '--', ' UNION ', '\\\'', '\\"'); $chars = array(';', '#', '/*', '*/', '--', '\\\'', '\\"'); $string = str_replace('\\\\', '', $string); $string = preg_replace('/(^|[^\\\])([\'"])\\2/is', '$1', $string); $string = preg_replace('/(^|[^\\\])([\'"])(.*?[^\\\])\\2/is', '$1', $string); $ok = true;