Changeset 6180 for trunk/wp-includes/general-template.php
- Timestamp:
- 10/02/2007 06:45:47 PM (18 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/wp-includes/general-template.php
r6148 r6180 209 209 if ( !empty($author_name) ) { 210 210 // We do a direct query here because we don't cache by nicename. 211 $title = $wpdb->get_var( "SELECT display_name FROM $wpdb->users WHERE user_nicename = '$author_name'");211 $title = $wpdb->get_var($wpdb->prepare("SELECT display_name FROM $wpdb->users WHERE user_nicename = %s", $author_name)); 212 212 } 213 213 … … 256 256 if ( intval($p) || '' != $name ) { 257 257 if ( !$p ) 258 $p = $wpdb->get_var( "SELECT ID FROM $wpdb->posts WHERE post_name = '$name'");258 $p = $wpdb->get_var($wpdb->prepare("SELECT ID FROM $wpdb->posts WHERE post_name = %s", $name)); 259 259 $post = & get_post($p); 260 260 $title = $post->post_title; … … 364 364 365 365 if ( '' != $limit ) { 366 $limit = (int) $limit;366 $limit = abs(intval($limit)); 367 367 $limit = ' LIMIT '.$limit; 368 368 }
Note: See TracChangeset
for help on using the changeset viewer.