WordPress.org

Make WordPress Core


Ignore:
Timestamp:
04/14/2008 04:13:25 PM (14 years ago)
Author:
ryan
Message:

Prepare DB queries in more places. Props filosofo. see #6644

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/includes/comment.php

    r7609 r7645  
    44    global $wpdb;
    55
    6     return $wpdb->get_var("SELECT comment_post_ID FROM $wpdb->comments
    7             WHERE comment_author = '$comment_author' AND comment_date = '$comment_date'");
     6    return $wpdb->get_var( $wpdb->prepare("SELECT comment_post_ID FROM $wpdb->comments
     7            WHERE comment_author = %s AND comment_date = %s", $comment_author, $comment_date) );
    88}
    99
     
    6868    global $wpdb;
    6969    $post_id = (int) $post_id;
    70     $pending = $wpdb->get_var( "SELECT COUNT(*) FROM $wpdb->comments WHERE comment_post_ID = $post_id AND comment_approved = '0'" );
     70    $pending = $wpdb->get_var( $wpdb->prepare("SELECT COUNT(*) FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_approved = '0'", $post_id) );
    7171    return $pending;
    7272}
Note: See TracChangeset for help on using the changeset viewer.