From 0e34bade9cc2fa831f9c8a344b2ebfdf4047848c Mon Sep 17 00:00:00 2001 From: Till Brehm <tbrehm@ispconfig.org> Date: Mon, 27 Oct 2014 13:53:37 +0100 Subject: [PATCH] Fixed: FS#3718 - SQL injection checker false positive alert in APS installer --- interface/lib/classes/db_mysql.inc.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/interface/lib/classes/db_mysql.inc.php b/interface/lib/classes/db_mysql.inc.php index d4ba79c592..7331463c51 100644 --- a/interface/lib/classes/db_mysql.inc.php +++ b/interface/lib/classes/db_mysql.inc.php @@ -132,6 +132,11 @@ class db extends mysqli if($ids_config['sql_scan_enabled'] == 'yes') { + // Remove whitespace + $string = trim($string); + if(substr($string,-1) == ';') $string = substr($string,0,-1); + + // Save original string $string_orig = $string; //echo $string; -- GitLab