Make WordPress Core


Ignore:
Timestamp:
12/16/2010 02:22:41 PM (15 years ago)
Author:
ryan
Message:

Add like_escape() to some queries. fixes #15764

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/class-wp-xmlrpc-server.php

    r16900 r16999  
    33683368                // ...or a string #title, a little more complicated
    33693369                $title = preg_replace('/[^a-z0-9]/i', '.', $urltest['fragment']);
    3370                 $sql = $wpdb->prepare("SELECT ID FROM $wpdb->posts WHERE post_title RLIKE %s", $title);
     3370                $sql = $wpdb->prepare("SELECT ID FROM $wpdb->posts WHERE post_title RLIKE %s", like_escape( $title ) );
    33713371                if (! ($post_ID = $wpdb->get_var($sql)) ) {
    33723372                    // returning unknown error '0' is better than die()ing
Note: See TracChangeset for help on using the changeset viewer.