diff --git a/public/API/queries/blogPost.php b/public/API/queries/blogPost.php index 6f3d732706defa0f7675c2050c76e4c97e0145e5..117ecf096b78d8f2ad98d704be508329f66ea0f6 100644 --- a/public/API/queries/blogPost.php +++ b/public/API/queries/blogPost.php @@ -39,6 +39,7 @@ function blogPost($id, $conn) function blogPosts($count, $contentLength, $conn) { $response = []; + $count = $conn->real_escape_string($count); $result = $conn->query("SELECT * FROM posts order by id desc limit $count"); if ($result->num_rows > 0) { while ($row = $result->fetch_assoc()) { @@ -62,4 +63,4 @@ function blogPosts($count, $contentLength, $conn) } return $response; -} \ No newline at end of file +} diff --git a/public/API/queries/comments.php b/public/API/queries/comments.php index 3b3d46ba952ab523e35140ffd1299ea0ee1c54dd..de1f3c4167b7ebe0b9e4f98f418aa181bd2cb565 100644 --- a/public/API/queries/comments.php +++ b/public/API/queries/comments.php @@ -18,6 +18,7 @@ $commentField = new ObjectType([ function comments($article, $conn) { $response = []; + $article = $conn->real_escape_string($article); $result = $conn->query("SELECT * FROM comments WHERE article='$article'"); while ($row = $result->fetch_assoc()) { $commentElement = [ diff --git a/public/API/queries/skills.php b/public/API/queries/skills.php index 31670650e1ff02c573b4c61eceaddea7f976061d..5bd97dad607c3b1ce3846d12983ef1388ff50e67 100644 --- a/public/API/queries/skills.php +++ b/public/API/queries/skills.php @@ -20,4 +20,4 @@ function getSkills() { array_push($response, $skill["Key"]); } return $response; -} \ No newline at end of file +}