Bug 7955: Followup : Check the syspref value (avoid sql injection)
authorJonathan Druart <jonathan.druart@biblibre.com>
Tue, 10 Jul 2012 14:00:54 +0000 (16:00 +0200)
committerPaul Poulain <paul.poulain@biblibre.com>
Wed, 1 Aug 2012 14:06:38 +0000 (16:06 +0200)
commit934a8a1156f20807c1c132b451c452d39569d1fe
treed9f80817b31d9cd9d3819e812db7041167738336
parent8c309c1a67294439b882aeea06cc63670480268f
Bug 7955: Followup : Check the syspref value (avoid sql injection)

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
Works as expected. Fields with disallowed characters do not show up.
Added 'if $debug' to an pseudo-unconditional warn.

Signed-off-by: Paul Poulain <paul.poulain@biblibre.com>
C4/Members/Statistics.pm
members/statistics.pl