diff -r c255196bc447 -r 90fbb34b3d97 inc/users.inc.php --- a/inc/users.inc.php Tue Mar 25 22:45:31 2008 +0000 +++ b/inc/users.inc.php Wed Mar 26 07:40:14 2008 +0000 @@ -275,7 +275,7 @@ // we have been given. User wants a change of username. Now, make // sure it doesn't already exist. - $query = "SELECT id FROM users WHERE username = " . $db->query($user); + $query = "SELECT id FROM users WHERE username = " . $db->quote($user); $result = $db->query($query); if (PEAR::isError($response)) { error($response->getMessage()); return false; }