From 53bee7f8fc073d2128f9b542e2b676b4fd3e8b84 Mon Sep 17 00:00:00 2001 From: Ludovic Pouzenc Date: Sun, 28 Aug 2016 10:06:21 +0200 Subject: Security issue : SET NAMES does not affect mysql_real_espace_string() --- api/gen_conf.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/gen_conf.php b/api/gen_conf.php index 39e54a3..d5e61a1 100644 --- a/api/gen_conf.php +++ b/api/gen_conf.php @@ -25,7 +25,7 @@ if (mysqli_connect_errno()) { die(mysqli_connect_error()); } unset($db_config); -$mysqli->query("SET NAMES 'utf8'"); +$mysqli->set_charset("utf8") or die($mysqli->error); $descriptorspec = array( -- cgit v1.1