Skip to:
Content

BuddyPress.org

Changeset 6493


Ignore:
Timestamp:
11/08/2012 07:04:54 PM (13 years ago)
Author:
johnjamesjacoby
Message:

Do not prepare() queries without string replacements in: bp-core-classes.php.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/bp-core/bp-core-classes.php

    r6488 r6493  
    203203                $sql['select']  = "SELECT DISTINCT u.{$this->uid_name} as id FROM {$wpdb->usermeta} u";
    204204                $sql['where'][] = $wpdb->prepare( "u.meta_key = %s", bp_get_user_meta_key( 'last_activity' ) );
    205                 $sql['where'][] = $wpdb->prepare( 'u.meta_value >= DATE_SUB( UTC_TIMESTAMP(), INTERVAL 5 MINUTE )' );
     205                $sql['where'][] = 'u.meta_value >= DATE_SUB( UTC_TIMESTAMP(), INTERVAL 5 MINUTE )';
    206206                $sql['orderby'] = "ORDER BY u.meta_value";
    207207                $sql['order']   = "DESC";
     
    376376
    377377        // Get the specific user ids
    378         $this->user_ids = $wpdb->get_col( $wpdb->prepare( "{$this->uid_clauses['select']} {$this->uid_clauses['where']} {$this->uid_clauses['orderby']} {$this->uid_clauses['order']} {$this->uid_clauses['limit']}" ) );
     378        $this->user_ids = $wpdb->get_col( "{$this->uid_clauses['select']} {$this->uid_clauses['where']} {$this->uid_clauses['orderby']} {$this->uid_clauses['order']} {$this->uid_clauses['limit']}" );
    379379
    380380        // Get the total user count
Note: See TracChangeset for help on using the changeset viewer.