@@ -261,7 +261,7 @@ public static function send_invitation_friend ($user_id,$friend_id,$message_titl
261261		$ tbl_messageget_main_table (TABLE_MAIN_MESSAGE );
262262		$ user_idintval ($ user_id
263263		$ friend_idintval ($ friend_id
264- 		$ message_titleescape_string ($ message_title
264+ 		$ message_title   = Database::escape_string ($ message_title
265265		$ message_contentescape_string ($ message_content
266266
267267		$ current_datedate ('Y-m-d H:i:s ' ,time ());		
@@ -280,8 +280,8 @@ public static function send_invitation_friend ($user_id,$friend_id,$message_titl
280280			$ res_if_existquery ($ sql_if_exist__FILE__ ,__LINE__ );
281281			$ row_if_existfetch_array ($ res_if_exist'ASSOC ' );
282282			if  ($ row_if_exist'count ' ]==1 ) {
283- 				// $sql_if_exist_up='UPDATE '.$tbl_message.'SET msg_status=5  WHERE user_sender_id='.$user_id.' AND user_receiver_id='.$friend_id.' WHERE  msg_status=5 ';
284- 				$ sql_if_exist_up'UPDATE  ' .$ tbl_message'SET msg_status=5, set content =  ' .$ message_content' WHERE id= ' .$ row_if_exist'id ' ].'' ;
283+ 				$ sql_if_exist_up'UPDATE  ' .$ tbl_message'SET msg_status=5, content = "  '  . $ message_content . ' "   WHERE user_sender_id=$ user_id' AND user_receiver_id= ' .$ friend_id' AND  msg_status = 7   ' ;
284+ 				// $sql_if_exist_up='UPDATE '.$tbl_message.'SET msg_status=5, set content = '.$message_content.' WHERE id='.$row_if_exist['id'].'';
285285				Database::query ($ sql_if_exist_up__FILE__ ,__LINE__ );
286286				return  true ;
287287			} else  {
0 commit comments