Make WordPress Core


Ignore:
Timestamp:
09/27/2009 05:33:56 AM (15 years ago)
Author:
markjaquith
Message:

esc_sql() for wp-includes

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/user.php

    r11930 r11978  
    154154    global $wpdb;
    155155    if ( !$user )
    156         $user = $wpdb->escape($_COOKIE[USER_COOKIE]);
     156        $user = esc_sql( $_COOKIE[USER_COOKIE] );
    157157    return $wpdb->get_var( $wpdb->prepare("SELECT $field FROM $wpdb->users WHERE user_login = %s", $user) );
    158158}
Note: See TracChangeset for help on using the changeset viewer.