Show
Ignore:
Timestamp:
04/14/08 16:13:25 (5 months ago)
Author:
ryan
Message:

Prepare DB queries in more places. Props filosofo. see #6644

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/wp-admin/import/dotclear.php

    r7397 r7645  
    1414    { 
    1515        global $wpdb; 
    16         return $wpdb->get_var('SELECT count(*) FROM '.$wpdb->comments.' WHERE comment_post_ID = '.$post_ID); 
     16        return $wpdb->get_var( $wpdb->prepare("SELECT count(*) FROM $wpdb->comments WHERE comment_post_ID = %d", $post_ID) ); 
    1717    } 
    1818} 
     
    2323    { 
    2424        global $wpdb; 
    25         return $wpdb->get_var('SELECT link_id FROM '.$wpdb->links.' WHERE link_name = "'.$linkname.'"'); 
     25        return $wpdb->get_var( $wpdb->prepare("SELECT link_id FROM $wpdb->links WHERE link_name = %s", $linkname) ); 
    2626    } 
    2727}