Ticket #6644: prepared_queries12.diff
| File prepared_queries12.diff, 2.9 KB (added by , 18 years ago) |
|---|
-
wp-admin/import/dotclear.php
13 13 function get_comment_count($post_ID) 14 14 { 15 15 global $wpdb; 16 return $wpdb->get_var( 'SELECT count(*) FROM '.$wpdb->comments.' WHERE comment_post_ID = '.$post_ID);16 return $wpdb->get_var( $wpdb->prepare("SELECT count(*) FROM $wpdb->comments WHERE comment_post_ID = %d", $post_ID) ); 17 17 } 18 18 } 19 19 … … 22 22 function link_exists($linkname) 23 23 { 24 24 global $wpdb; 25 return $wpdb->get_var( 'SELECT link_id FROM '.$wpdb->links.' WHERE link_name = "'.$linkname.'"');25 return $wpdb->get_var( $wpdb->prepare("SELECT link_id FROM $wpdb->links WHERE link_name = %s", $linkname) ); 26 26 } 27 27 } 28 28 -
wp-admin/import/blogger.php
641 641 $host = $this->blogs[$importing_blog]['host']; 642 642 643 643 // Get an array of posts => authors 644 $post_ids = (array) $wpdb->get_col( "SELECT post_id FROM $wpdb->postmeta WHERE meta_key = 'blogger_blog' AND meta_value = '$host'");644 $post_ids = (array) $wpdb->get_col( $wpdb->prepare("SELECT post_id FROM $wpdb->postmeta WHERE meta_key = 'blogger_blog' AND meta_value = %s", $host) ); 645 645 $post_ids = join( ',', $post_ids ); 646 646 $results = (array) $wpdb->get_results("SELECT post_id, meta_value FROM $wpdb->postmeta WHERE meta_key = 'blogger_author' AND post_id IN ($post_ids)"); 647 647 foreach ( $results as $row ) … … 658 658 $post_ids = (array) array_keys( $authors_posts, $this->blogs[$importing_blog]['authors'][$author][0] ); 659 659 $post_ids = join( ',', $post_ids); 660 660 661 $wpdb->query( "UPDATE $wpdb->posts SET post_author = $user_id WHERE id IN ($post_ids)");661 $wpdb->query( $wpdb->prepare("UPDATE $wpdb->posts SET post_author = %d WHERE id IN ($post_ids)", $user_id) ); 662 662 $this->blogs[$importing_blog]['authors'][$author][1] = $user_id; 663 663 } 664 664 $this->save_vars(); -
wp-admin/import/textpattern.php
8 8 function get_comment_count($post_ID) 9 9 { 10 10 global $wpdb; 11 return $wpdb->get_var( 'SELECT count(*) FROM '.$wpdb->comments.' WHERE comment_post_ID = '.$post_ID);11 return $wpdb->get_var( $wpdb->prepare("SELECT count(*) FROM $wpdb->comments WHERE comment_post_ID = %d", $post_ID) ); 12 12 } 13 13 } 14 14 … … 17 17 function link_exists($linkname) 18 18 { 19 19 global $wpdb; 20 return $wpdb->get_var( 'SELECT link_id FROM '.$wpdb->links.' WHERE link_name = "'.$wpdb->escape($linkname).'"');20 return $wpdb->get_var( $wpdb->prepare("SELECT link_id FROM $wpdb->links WHERE link_name = %s", $linkname) ); 21 21 } 22 22 } 23 23