use raw db queries wherever query items could contain '%'

This commit is contained in:
Friendika 2010-11-09 15:11:47 -08:00
commit f7c0480f1b
4 changed files with 13 additions and 3 deletions

View file

@ -249,7 +249,7 @@ function profiles_content(&$a) {
dbesc_array($r1[0]);
$r2 = q("INSERT INTO `profile` (`"
$r2 = dbq("INSERT INTO `profile` (`"
. implode("`, `", array_keys($r1[0]))
. "`) VALUES ('"
. implode("', '", array_values($r1[0]))