Skip to content
Snippets Groups Projects
Commit bc8b5ca1 authored by Prasad's avatar Prasad
Browse files

Merge branch 'sqlinjections' into 'master'

Sqlinjections

See merge request !413
parents 8a327711 beeccd37
No related branches found
No related tags found
No related merge requests found
......@@ -125,7 +125,9 @@ class Calendar_Feed_Action extends Vtiger_BasicAjax_Action {
$queryGenerator->setFields(array_merge(array_merge($nameFields, array('id')), $fieldsList));
$query = $queryGenerator->getQuery();
$query.= " AND (($fieldsList[0] >= ? AND $fieldsList[1] < ?) OR ($fieldsList[1] >= ?)) ";
$startDateColumn = Vtiger_Util_Helper::validateStringForSql($fieldsList[0]);
$endDateColumn = Vtiger_Util_Helper::validateStringForSql($fieldsList[1]);
$query.= " AND (($startDateColumn >= ? AND $endDateColumn < ?) OR ($endDateColumn >= ?)) ";
$params = array($start,$end,$start);
$query.= " AND vtiger_crmentity.smownerid IN (".generateQuestionMarks($userAndGroupIds).")";
$params = array_merge($params, $userAndGroupIds);
......
......@@ -57,4 +57,4 @@ class Emails_DownloadFile_Action extends Vtiger_Action_Controller {
}
}
?>
?>
\ No newline at end of file
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment