From 692510beefb683320348b2848fa7ac2c6f497c39 Mon Sep 17 00:00:00 2001 From: jakubvrana Date: Thu, 26 Nov 2009 14:19:09 +0000 Subject: [PATCH] Use editVal in emailProcess fields git-svn-id: https://adminer.svn.sourceforge.net/svnroot/adminer/trunk@1254 7c3ca157-0c34-0410-bff1-cbf682f78f5c --- editor/include/adminer.inc.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/editor/include/adminer.inc.php b/editor/include/adminer.inc.php index f2510843..5fc50a84 100644 --- a/editor/include/adminer.inc.php +++ b/editor/include/adminer.inc.php @@ -359,10 +359,11 @@ ORDER BY ORDINAL_POSITION"); $headers .= $eol . "MIME-Version: 1.0$eol" . "X-Mailer: Adminer Editor" . ($_POST["email_from"] ? $eol . "From: " . str_replace("\n", "", $_POST["email_from"]) : "") //! should escape display name ; + $fields = fields($_GET["select"]); foreach ($this->rowDescriptions($rows, $foreignKeys) as $row) { $replace = array(); foreach ($matches[1] as $val) { - $replace['{$' . "$val}"] = $row[$val]; //! allow literal {$name} + $replace['{$' . "$val}"] = $this->editVal($row[$val], $fields[$val]); //! allow literal {$name} } $email = $row[$_POST["email_field"]]; if (is_email($email) && mail($email, email_header(strtr($subject, $replace)), $beginning . strtr($message, $replace) . $attachments, $headers)) {