DataObjects/Core_enum.php
authorMicheal <micheal@roojs.com>
Mon, 26 Jan 2015 08:34:14 +0000 (16:34 +0800)
committerMicheal <micheal@roojs.com>
Mon, 26 Jan 2015 08:34:14 +0000 (16:34 +0800)
DataObjects/Core_enum.php

index 7c6b792..cb16941 100644 (file)
@@ -123,7 +123,7 @@ class Pman_Core_DataObjects_Core_enum extends DB_DataObject
         $tn = $this->tableName();
         $x = $this->factory($tn);
         if(!($old->etype == $request['etype'] && $old->name == $request['name'])){
-            $x->whereAdd("etype = '{$request['etype']}' AND name = '{$request['name']}'");
+            $x->whereAdd("etype = '{$this->escape($request['etype'])}' AND name = '{$this->escape($request['name'])}'");
             $x->find(true);
             if($x->count() > 0){
                 $roo->jerr('is exsiting');