WordPress.org

Make WordPress Core


Ignore:
Timestamp:
04/14/2008 04:13:25 PM (14 years ago)
Author:
ryan
Message:

Prepare DB queries in more places. Props filosofo. see #6644

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/includes/export.php

    r7299 r7645  
    1818if ( $author and $author != 'all' ) {
    1919    $author_id = (int) $author;
    20     $where = " WHERE post_author = '$author_id' ";
     20    $where = $wpdb->prepare(" WHERE post_author = %d ", $author_id);
    2121}
    2222
     
    218218<?php } ?>
    219219<?php
    220 $postmeta = $wpdb->get_results("SELECT * FROM $wpdb->postmeta WHERE post_id = $post->ID");
     220$postmeta = $wpdb->get_results( $wpdb->prepare("SELECT * FROM $wpdb->postmeta WHERE post_id = %d", $post->ID) );
    221221if ( $postmeta ) {
    222222?>
     
    229229<?php } ?>
    230230<?php
    231 $comments = $wpdb->get_results("SELECT * FROM $wpdb->comments WHERE comment_post_ID = $post->ID");
     231$comments = $wpdb->get_results( $wpdb->prepare("SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d", $post->ID) );
    232232if ( $comments ) { foreach ( $comments as $c ) { ?>
    233233<wp:comment>
Note: See TracChangeset for help on using the changeset viewer.