<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[FrontAccounting forum — Import CSV Items]]></title>
	<link rel="self" href="https://frontaccounting.com/punbb/extern.php?action=feed&amp;tid=75&amp;type=atom" />
	<updated>2008-09-08T11:52:38Z</updated>
	<generator>PunBB</generator>
	<id>https://frontaccounting.com/punbb/viewtopic.php?id=75</id>
		<entry>
			<title type="html"><![CDATA[Re: Import CSV Items]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=1099#p1099" />
			<content type="html"><![CDATA[<p>Your solution is perfect.</p><p>/Joe</p>]]></content>
			<author>
				<name><![CDATA[joe]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=3</uri>
			</author>
			<updated>2008-09-08T11:52:38Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=1099#p1099</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Import CSV Items]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=1098#p1098" />
			<content type="html"><![CDATA[<p>Is the solution I used correct or does it cause any risks/issues?</p>]]></content>
			<author>
				<name><![CDATA[roger]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=207</uri>
			</author>
			<updated>2008-09-08T11:36:53Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=1098#p1098</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Import CSV Items]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=1097#p1097" />
			<content type="html"><![CDATA[<p>We are aware of this problem. We had to escape all the input database fields in FrontAccounting to eliminate spammer injections. Spammers could add html code into the fields and thereby inject the script.</p><p>/Joe</p>]]></content>
			<author>
				<name><![CDATA[joe]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=3</uri>
			</author>
			<updated>2008-09-08T07:11:48Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=1097#p1097</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Import CSV Items]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=1094#p1094" />
			<content type="html"><![CDATA[<p>Hi Joe,<br />I check the module and found an error:<br />On line 38 you use db_escape() function to clean the $description field. This results in the addition of single quotes arround the quotes in $description.<br />Later in line 67 and 85 when building the SQL statements for update and insert there is yet an other sigle quote arround %description resulting in a SQL error.</p><p>Removing these quotes seams to solve the problem.</p><p>Regards</p><p>Roger</p>]]></content>
			<author>
				<name><![CDATA[roger]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=207</uri>
			</author>
			<updated>2008-09-08T02:40:12Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=1094#p1094</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Import CSV Items]]></title>
			<link rel="alternate" href="https://frontaccounting.com/punbb/viewtopic.php?pid=213#p213" />
			<content type="html"><![CDATA[<p>A module for importing Items from other systems has been added to the Download pages.</p><p>/Joe</p>]]></content>
			<author>
				<name><![CDATA[joe]]></name>
				<uri>https://frontaccounting.com/punbb/profile.php?id=3</uri>
			</author>
			<updated>2007-12-06T21:23:21Z</updated>
			<id>https://frontaccounting.com/punbb/viewtopic.php?pid=213#p213</id>
		</entry>
</feed>
