From 86853d4d0fd66c277746e9e0cf07fbecbfbbc362 Mon Sep 17 00:00:00 2001
From: Till Brehm <tbrehm@ispconfig.org>
Date: Wed, 20 Apr 2016 12:38:50 -0400
Subject: [PATCH] Fixed #3835 Delete MailBackup not working - Log shows a warning about SQL Injection
---
interface/lib/classes/plugin_backuplist_mail.inc.php | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/interface/lib/classes/plugin_backuplist_mail.inc.php b/interface/lib/classes/plugin_backuplist_mail.inc.php
index 2c3e7a3..512fb8c 100644
--- a/interface/lib/classes/plugin_backuplist_mail.inc.php
+++ b/interface/lib/classes/plugin_backuplist_mail.inc.php
@@ -75,7 +75,7 @@
if($tmp['number'] == 0) {
$message .= $wb['delete_info_txt'];
$sql = "INSERT INTO sys_remoteaction (server_id, tstamp, action_type, action_param, action_state, response) " .
- "VALUES (?, ?, 'backup_delete_mail, ?, 'pending', '')";
+ "VALUES (?, ?, 'backup_delete_mail', ?, 'pending', '')";
$app->db->query($sql, $this->form->dataRecord['server_id'], time(), $backup_id);
} else {
$error .= $wb['delete_pending_txt'];
--
Gitblit v1.9.1