From 43fa235da354c8b53aa69ba745c1d398a758fcaf Mon Sep 17 00:00:00 2001
From: svncommit <devs@roundcube.net>
Date: Wed, 26 Oct 2005 05:42:19 -0400
Subject: [PATCH] 

---
 program/steps/settings/edit_identity.inc |   15 +++++++--------
 1 files changed, 7 insertions(+), 8 deletions(-)

diff --git a/program/steps/settings/edit_identity.inc b/program/steps/settings/edit_identity.inc
index f9cbc7c..dc2f149 100644
--- a/program/steps/settings/edit_identity.inc
+++ b/program/steps/settings/edit_identity.inc
@@ -22,13 +22,12 @@
 if (($_GET['_iid'] || $_POST['_iid']) && $_action=='edit-identity')
   {
   $id = $_POST['_iid'] ? $_POST['_iid'] : $_GET['_iid'];
-  $DB->query(sprintf("SELECT * FROM %s
-                      WHERE  identity_id=%d
-                      AND    user_id=%d
-                      AND    del!='1'",
-                     get_table_name('identities'),
-                     $id,
-                     $_SESSION['user_id']));
+  $DB->query("SELECT * FROM ".get_table_name('identities')."
+              WHERE  identity_id=?
+              AND    user_id=?
+              AND    del<>'1'",
+              $id,
+              $_SESSION['user_id']);
   
   $IDENTITY_RECORD = $DB->fetch_assoc();
   
@@ -88,7 +87,7 @@
 
     $out .= sprintf("<tr><td class=\"title\"><label for=\"%s\">%s</label></td><td>%s</td></tr>\n",
                     $attrib['id'],
-                    rcube_label($label),
+                    rep_specialchars_output(rcube_label($label)),
                     $value);
     }
 

--
Gitblit v1.9.1