From 86853d4d0fd66c277746e9e0cf07fbecbfbbc362 Mon Sep 17 00:00:00 2001 From: Till Brehm <tbrehm@ispconfig.org> Date: Wed, 20 Apr 2016 12:38:50 -0400 Subject: [PATCH] Fixed #3835 Delete MailBackup not working - Log shows a warning about SQL Injection --- interface/lib/classes/plugin_backuplist_mail.inc.php | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-) diff --git a/interface/lib/classes/plugin_backuplist_mail.inc.php b/interface/lib/classes/plugin_backuplist_mail.inc.php index 2c3e7a3..512fb8c 100644 --- a/interface/lib/classes/plugin_backuplist_mail.inc.php +++ b/interface/lib/classes/plugin_backuplist_mail.inc.php @@ -75,7 +75,7 @@ if($tmp['number'] == 0) { $message .= $wb['delete_info_txt']; $sql = "INSERT INTO sys_remoteaction (server_id, tstamp, action_type, action_param, action_state, response) " . - "VALUES (?, ?, 'backup_delete_mail, ?, 'pending', '')"; + "VALUES (?, ?, 'backup_delete_mail', ?, 'pending', '')"; $app->db->query($sql, $this->form->dataRecord['server_id'], time(), $backup_id); } else { $error .= $wb['delete_pending_txt']; -- Gitblit v1.9.1