summaryrefslogtreecommitdiff
path: root/www/api/cemails.php
diff options
context:
space:
mode:
Diffstat (limited to 'www/api/cemails.php')
-rw-r--r--www/api/cemails.php4
1 files changed, 2 insertions, 2 deletions
diff --git a/www/api/cemails.php b/www/api/cemails.php
index 0d067ea..bdb3363 100644
--- a/www/api/cemails.php
+++ b/www/api/cemails.php
@@ -15,8 +15,8 @@
along with this program; if not, write to the Free Software
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
*/
- $username = mysql_escape_string($_REQUEST['username']);
- $password = mysql_escape_string($_REQUEST['password']);
+ $username = mysql_real_escape_string($_REQUEST['username']);
+ $password = mysql_real_escape_string($_REQUEST['password']);
$query = "select * from `users` where `email`='$username' and (`password`=old_password('$password') or `password`=sha1('$password'))";
$res = mysql_query($query);