1
0
mirror of https://git.tt-rss.org/git/tt-rss.git synced 2025-12-13 22:55:55 +00:00

authenticate_user: properly escape input

This commit is contained in:
Andrew Dolgov
2009-05-12 00:33:40 +04:00
parent f574fec6a6
commit 2d969845f9

View File

@@ -1741,6 +1741,7 @@
$pwd_hash1 = encrypt_password($password);
$pwd_hash2 = encrypt_password($password, $login);
$login = db_escape_string($login);
if (defined('ALLOW_REMOTE_USER_AUTH') && ALLOW_REMOTE_USER_AUTH
&& $_SERVER["REMOTE_USER"] && $login != "admin") {