[otrs-cvs] ITSMChangeManagement/Kernel/System ITSMChange.pm, 1.281.2.1, 1.281.2.2

"CVS commits notifications of OTRS.org" <[email protected]> Fri, 28 Jun 2013 13:04:27 +0000
Newsgroups gmane.comp.otrs.cvs
Message-ID <[email protected]>
Comments:
Update of /home/cvs/ITSMChangeManagement/Kernel/System
In directory lancelot:/tmp/cvs-serv17507/Kernel/System

Modified Files:
      Tag: rel-3_1
	ITSMChange.pm 
Log Message:
Improved quoting for integer values to avoid possible security issues.

Author: ub

Index: ITSMChange.pm
===================================================================
RCS file: /home/cvs/ITSMChangeManagement/Kernel/System/ITSMChange.pm,v
retrieving revision 1.281.2.1
retrieving revision 1.281.2.2
diff -2 -u -d -r1.281.2.1 -r1.281.2.2
--- ITSMChange.pm	21 Nov 2012 17:58:05 -0000	1.281.2.1
+++ ITSMChange.pm	28 Jun 2013 13:04:22 -0000	1.281.2.2
@@ -1,5 +1,5 @@
 # --
 # Kernel/System/ITSMChange.pm - all change functions
-# Copyright (C) 2001-2012 OTRS AG, http://otrs.org/
+# Copyright (C) 2001-2013 OTRS AG, http://otrs.org/
 # --
 # $Id$
@@ -1967,7 +1967,7 @@
         next WORKORDERPARAM if !@{ $Param{$WorkOrderParam} };
 
-        # quote
+        # quote as integer
         for my $OneParam ( @{ $Param{$WorkOrderParam} } ) {
-            $OneParam = $DBObject->Quote($OneParam);
+            $OneParam = $DBObject->Quote( $OneParam, 'Integer' );
         }
 
---------------------------------------------------------------------
OTRS mailing list: cvs-log - Webpage: http://otrs.org/
Archive: http://lists.otrs.org/pipermail/cvs-log
To unsubscribe: http://lists.otrs.org/cgi-bin/listinfo/cvs-log