Joshua Wise c5a710e081 Escape $tag passed to Profile::getTaggedSubscribers()
This patch escapes the $tag parameter in
Profile::getTaggedSubscribers(). The parameter is not escaped either
in actions/subscriptions.php or in actions/apiuserfollowers.php. So
there is a potential for SQL injection here.
2013-07-16 10:14:38 -07:00
..
2011-08-22 17:52:02 -04:00
2011-08-22 17:52:02 -04:00
2011-08-22 17:52:02 -04:00
2011-08-22 17:52:02 -04:00
2013-06-15 12:07:34 -04:00
2011-08-22 17:52:02 -04:00
2011-10-20 12:50:39 -04:00
2011-08-22 17:52:02 -04:00
2011-08-22 17:52:02 -04:00
2011-08-27 16:05:58 -04:00
2013-06-04 16:30:40 -04:00