From c7a8deacd97242e33a1d4111ccd1da6810d28255 Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Sat, 19 Feb 2011 16:55:36 +0300 Subject: db_escape_string: remove tags by default (refs #323) --- db.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'db.php') diff --git a/db.php b/db.php index 844bd0e41..9b1ce5d84 100644 --- a/db.php +++ b/db.php @@ -41,7 +41,9 @@ function db_connect($host, $user, $pass, $db) { } } -function db_escape_string($s) { +function db_escape_string($s, $strip_tags = true) { + if ($strip_tags) $s = strip_tags($s); + if (DB_TYPE == "pgsql") { return pg_escape_string($s); } else { -- cgit v1.2.3