diff --git a/lib/visualpatterns/PatternListFromQuery.inc b/lib/visualpatterns/PatternListFromQuery.inc index 47c1498..c6d1db9 100644 --- a/lib/visualpatterns/PatternListFromQuery.inc +++ b/lib/visualpatterns/PatternListFromQuery.inc @@ -94,14 +94,14 @@ class PatternListFromQuery { switch ($this->aColumnTypes[$i]) { //plain text field case 1: - $sToRender .= "" . $this->aColumnNames[$i] . "" . $sql->f($this->aColumns[$i]) . "\n"; + $sToRender .= "" . $this->aColumnNames[$i] . "" . stripslashes($sql->f($this->aColumns[$i])) . "\n"; break; //text area case 2: $sToRender .= "" . $this->aColumnNames[$i] . "\n"; break; case 3: - $sToRender .= "" . $this->aColumnNames[$i] . "aHyperLinkURL[$i] . "?" . $this->replaceValues($this->aQueryStringText[$i], $sql) . "\">" . $sql->f($this->aColumns[$i]) . "\n"; + $sToRender .= "" . $this->aColumnNames[$i] . "aHyperLinkURL[$i] . "?" . $this->replaceValues($this->aQueryStringText[$i], $sql) . "\">" . stripslashes($sql->f($this->aColumns[$i])) . "\n"; break; default: break; diff --git a/lib/visualpatterns/PatternTableSqlQuery.inc b/lib/visualpatterns/PatternTableSqlQuery.inc index ce85372..56fd00f 100644 --- a/lib/visualpatterns/PatternTableSqlQuery.inc +++ b/lib/visualpatterns/PatternTableSqlQuery.inc @@ -119,19 +119,21 @@ class PatternTableSqlQuery { for ($i = 0; $i < count($this->aColumns); $i++) { switch ($this->aColumnTypes[$i]) { case 1: + //text $sToRender .= ""; if (isset($this->sImageURL)) { $sToRender .= $this->generateImageURL($this->sImageURL); } else if ($this->bUseImageURLFromQuery) { $sToRender .= $this->generateImageURL($sql->f("image_url")); } - if ($sql->f($this->aColumns[$i] != null)) { - $sToRender .= $sql->f($this->aColumns[$i]) . ""; + if ($sql->f($this->aColumns[$i] != null)) { + $sToRender .= stripslashes($sql->f($this->aColumns[$i])) . ""; } else { $sToRender .= " "; } break; case 3: + //hyperlink $sToRender .= "sLinkURL; for ($j = 0; $j < count($this->aDBQueryStringColumns); $j++) { if (strpos($sToRender, "?") === false) { @@ -147,7 +149,7 @@ class PatternTableSqlQuery { } else if ($this->bUseImageURLFromQuery) { $sToRender .= $this->generateImageURL($sql->f("image_url")); } - $sToRender .= $sql->f($this->aColumns[$i]) . "\n"; + $sToRender .= stripslashes($sql->f($this->aColumns[$i])) . "\n"; break; default: break;