security bugfix

SVN Revision: 718
This commit is contained in:
Christophe Romain 2007-02-02 10:58:40 +00:00
parent fcc4adcde5
commit 85a7a306ff
1 changed files with 2 additions and 1 deletions

View File

@ -821,12 +821,13 @@ record_to_string(#roster{us = {User, _Server},
in -> "I"; in -> "I";
none -> "N" none -> "N"
end, end,
SAskMessage = ejabberd_odbc:escape(AskMessage),
["'", Username, "'," ["'", Username, "',"
"'", SJID, "'," "'", SJID, "',"
"'", Nick, "'," "'", Nick, "',"
"'", SSubscription, "'," "'", SSubscription, "',"
"'", SAsk, "'," "'", SAsk, "',"
"'", AskMessage, "'," "'", SAskMessage, "',"
"'N', '', 'item'"]. "'N', '', 'item'"].
groups_to_string(#roster{us = {User, _Server}, groups_to_string(#roster{us = {User, _Server},