Sigh...
authorBrion Vibber <brion@users.mediawiki.org>
Wed, 1 Dec 2004 16:11:03 +0000 (16:11 +0000)
committerBrion Vibber <brion@users.mediawiki.org>
Wed, 1 Dec 2004 16:11:03 +0000 (16:11 +0000)
includes/SpecialListusers.php

index a44901b..b7913da 100644 (file)
@@ -108,13 +108,13 @@ class ListUsersPage extends QueryPage {
                        "LEFT JOIN $group ON ug_group = group_id ";
                
                if($this->requestedGroup != '') {
-                       $sql .=  "WHERE group_id= '$this->requestedGroup' ";
+                       $sql .=  "WHERE group_id= '" . IntVal( $this->requestedGroup ) . "' ";
                        if($this->requestedUser != '') {
-                               $sql .= "AND user_name = '$this->requestedUser' ";
+                               $sql .= "AND user_name = " . $dbr->addQuotes( $this->requestedUser ) . " ";
                        }
                } else {
                        if($this->requestedUser !='') {
-                               $sql .= "WHERE user_name = '$this->requestedUser' ";
+                               $sql .= "WHERE user_name = " . $dbr->addQuotes( $this->requestedUser ) . " ";
                        }       
                }