X-Git-Url: https://git.mxchange.org/?p=mailer.git;a=blobdiff_plain;f=inc%2Fmodules%2Fguest%2Fwhat-login.php;h=efaf745c31b68e4e2eec7f094356e73609993f2e;hp=76312e88df808e37719fa1447263e21c253b5084;hb=7eb9da85bfb337997a58a244cb610c97a8d10c13;hpb=ddba3ed27ba0836305f98763f3a8b0255218486e;ds=sidebyside diff --git a/inc/modules/guest/what-login.php b/inc/modules/guest/what-login.php index 76312e88df..efaf745c31 100644 --- a/inc/modules/guest/what-login.php +++ b/inc/modules/guest/what-login.php @@ -239,11 +239,11 @@ if (IS_MEMBER()) { if ($probe_nickname) { // Nickname entered $result = SQL_QUERY_ESC("SELECT userid, status FROM "._MYSQL_PREFIX."_user_data WHERE nickname='%s' OR email='%s' LIMIT 1", - array(addslashes($uid), $_POST['email']), __FILE__, __LINE__); + array($uid, $_POST['email']), __FILE__, __LINE__); } else { // Direct userid entered $result = SQL_QUERY_ESC("SELECT userid, status FROM "._MYSQL_PREFIX."_user_data WHERE userid=%s OR email='%s' LIMIT 1", - array($uid, $_POST['email']), __FILE__, __LINE__); + array(bigintval($uid), $_POST['email']), __FILE__, __LINE__); } // Any entry found?