db_escape_string() is target as a helper function for _db_query_callback(), where db_escape_table() is safe for both column and table name escape. node_load() wrongly mix them up.

CommentFileSizeAuthor
node_load-db_escape_table-0.1.patch780 byteshswong3i

Comments

webernet’s picture

Status: Needs review » Closed (duplicate)