Fixes 26544

[TFS Changeset #64975]
This commit is contained in:
hartvig
2010-03-25 09:35:40 +00:00
parent 968d043489
commit f7e71efa54

View File

@@ -22,7 +22,7 @@ namespace umbraco.editorControls
string v = "";
try
{
IRecordsReader dr = SqlHelper.ExecuteReader("Select [value] from cmsDataTypeprevalues where id in (" + Value.ToString() +")");
IRecordsReader dr = SqlHelper.ExecuteReader("Select [value] from cmsDataTypeprevalues where id in (" + SqlHelper.EscapeString(Value.ToString()) + ")");
while (dr.Read()) {
if (v.Length == 0)