diff --git a/dump.inc.php b/dump.inc.php index e365bfcf..80a2c310 100644 --- a/dump.inc.php +++ b/dump.inc.php @@ -36,7 +36,7 @@ function dump($db) { $result1 = $mysql->query("SELECT * FROM " . idf_escape($row["Name"])); //! enum and set as numbers if ($result1) { while ($row1 = $result1->fetch_row()) { - echo "INSERT INTO " . idf_escape($row["Name"]) . " VALUES ('" . implode("', '", array_map(array($mysql, 'real_escape_string'), $row1)) . "');\n"; + echo "INSERT INTO " . idf_escape($row["Name"]) . " VALUES ('" . implode("', '", array_map(array($mysql, 'escape_string'), $row1)) . "');\n"; } $result1->free(); } diff --git a/functions.inc.php b/functions.inc.php index 7d0546a5..5b1d3d44 100644 --- a/functions.inc.php +++ b/functions.inc.php @@ -300,7 +300,7 @@ function process_input($name, $field) { } elseif ($field["type"] == "enum") { return (isset($_GET["default"]) ? "'" . $mysql->escape_string($value) . "'" : intval($value)); } elseif ($field["type"] == "set") { - return (isset($_GET["default"]) ? "'" . implode(",", array_map(array($mysql, 'real_escape_string'), (array) $value)) . "'" : array_sum((array) $value)); + return (isset($_GET["default"]) ? "'" . implode(",", array_map(array($mysql, 'escape_string'), (array) $value)) . "'" : array_sum((array) $value)); } elseif (preg_match('~binary|blob~', $field["type"])) { $file = get_file($name); if (!is_string($file) && !$field["null"]) {