Merge pull request #1312 from franzliedke/patch-53

DB::escape()
This commit is contained in:
Taylor Otwell
2013-01-05 13:03:31 -08:00
2 changed files with 14 additions and 1 deletions

View File

@@ -145,7 +145,7 @@ class Profiler {
{
foreach ($bindings as $binding)
{
$binding = Database::connection()->pdo->quote($binding);
$binding = Database::escape($binding);
$sql = preg_replace('/\?/', $binding, $sql, 1);
$sql = htmlspecialchars($sql);