From afb24c37ab05b694b5dc01e5a155875f3ce4d13b Mon Sep 17 00:00:00 2001 From: denise Date: Thu, 9 May 2013 16:07:34 -0400 Subject: [PATCH] CC-5121: fix some SQL statements not being escaped/prepared --- airtime_mvc/application/models/StoredFile.php | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/airtime_mvc/application/models/StoredFile.php b/airtime_mvc/application/models/StoredFile.php index 7dd74c62b..0d186597c 100644 --- a/airtime_mvc/application/models/StoredFile.php +++ b/airtime_mvc/application/models/StoredFile.php @@ -1177,12 +1177,7 @@ WHERE (id != -2 AND (soundcloud_upload_time >= (now() - (INTERVAL '1 day'))) SQL; - $params = array( - ':id1' => -2, - ':id2' => -3 - ); - $rows = Application_Common_Database::prepareAndExecute($sql, $params, - Application_Common_Database::ALL); + $rows = Application_Common_Database::prepareAndExecute($sql); return count($rows); } catch (Exception $e) {