View Single Post
  #16  
Old 04-03-2009, 02:11 PM
kisazeky kisazeky is offline
Member
 
Join Date: Mar 2009
Posts: 44
Credits: 19,316
kisazeky
Default RE: Rename adoptables (Updated!!)

No, don't do that.

Add

PHP Code:
if (isset($_POST['newname'])) $newname cleanQuery($_POST['newname']); 
below

PHP Code:
$newname $_POST["newname"]; 
Edit: Wait a minute, I just realized. Rusnak had the post data things before the connect to database script. That makes sense, hijackers can't input manipulative data if they don't have access to the database yet.