-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Alex Powell wrote:
Oh and while I'm at it is there any reason why line 161 of \includes\SearchEngine.php cannot be updated to :
return "\x22A-Za-z_'0-9\x80-\xFF\-";
This allows for quoted searches to be passed into the MySQL query engine. Or am I introducing a security hole?
Are you looking at a really old version? We've supported quoted searches for a while.
- -- brion