Hi,

On 6/9/07, Nicolas Rachinsky <[EMAIL PROTECTED]> wrote:
Hallo,

program/include/main.inc, line 608:
        ($sql_result = $DB->query(preg_replace('/%u/', $user, 
$CONFIG['virtuser_query']))) &&

Shouldn't the username be quoted correctly before inserted into the
database query?

Looks a bit weird - let me have a look.

Till


Reply via email to