Commit 2a21651a authored by Mike Sheldon's avatar Mike Sheldon

Quote arguments in getUserList correctly

parent 336204c9
......@@ -187,7 +187,8 @@ class Server {
static function getUserList($alpha) {
global $adodb;
$query = 'SELECT username from Users where username LIKE \'' . $alpha . '%\'';
$alpha .= '%';
$query = 'SELECT username from Users where username LIKE ' . $adodb->qstr($alpha);
$adodb->SetFetchMode(ADODB_FETCH_ASSOC);
$data = $adodb->CacheGetAll(7200, $query);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment