[wp-trac] [WordPress Trac] #11819: Use mysql_real_escape_string instead of addslashes

WordPress Trac noreply at wordpress.org
Mon Mar 18 18:15:24 UTC 2013


#11819: Use mysql_real_escape_string instead of addslashes
--------------------------+----------------------
 Reporter:  hakre         |       Owner:  ryan
     Type:  defect (bug)  |      Status:  closed
 Priority:  high          |   Milestone:
Component:  Security      |     Version:  2.5
 Severity:  critical      |  Resolution:  wontfix
 Keywords:                |
--------------------------+----------------------
Changes (by ryan):

 * keywords:  dev-feedback needs-patch close =>
 * status:  reopened => closed
 * resolution:   => wontfix
 * milestone:  3.6 =>


Comment:

 This has strayed well past the original subject.  I think this plus #21767
 document the reasons why we're not going to turn all weak escapes into
 real well enough. #21767 and #22325 document how the other issues raised
 here are going to be addressed. Resolving this as a wontfix for the
 original report.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11819#comment:32>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list