Changeset 114


Ignore:
Timestamp:
11/20/2007 04:27:02 PM (4 years ago)
Author:
guyru
Message:

fixed escaping error

Location:
trunk/www
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/www/htdocs/feedout.php

    r113 r114  
    1212} 
    1313 
    14 $name=mysql_real_escape_string($_POST['name']); 
     14$name=$_POST['name']; 
    1515checkOK($name); 
    16 $email=mysql_real_escape_string($_POST['email']); 
     16$email=$_POST['email']; 
    1717checkOK($email); 
    18 $comments=mysql_real_escape_string($_POST['comments']); 
     18$comments=$_POST['comments']; 
    1919//the checking of the comments is completly uneeded 
    2020//checkOK($comments); 
    2121 
    22 $to=mysql_real_escape_string("openyahtzee-users@lists.sourceforge.net"); 
     22$to="openyahtzee-users@lists.sourceforge.net"; 
    2323 
    2424$message="The following feedback was sent to the list by $name <$email>.\n\n$comments"; 
  • trunk/www/scripts/db2mail.php

    r113 r114  
    1111$total = 0; 
    1212while ($line = mysql_fetch_array($result, MYSQL_ASSOC)) { 
    13   $line['ID'] = stripcslashes ($line['ID']); 
    14   $line['subject'] = stripcslashe($line['subject']); 
    15   $line['recipient'] = stripcslashe($line['recipient']); 
    16   $line['headers'] = stripcslasheb($line['headers']); 
     13  $line['ID'] = breakapart ($line['ID']); 
     14  $line['subject'] = breakapart($line['subject']); 
     15  $line['recipient'] = breakapart($line['recipient']); 
     16  $line['headers'] = breakapart($line['headers']); 
    1717  $line['headers'] .= "Message-DBID: ". $line['ID'] ."\n"; 
    1818 
  • trunk/www/scripts/mailer.php

    r74 r114  
    55   or die('Could not connect: ' . mysql_error()); 
    66  $to = addslashes($to); 
    7   $subject = addslashes($subject); 
    8   $message = addslashes($message); 
    9   $headers = addslashes($headers);   
     7  $subject = mysql_real_escape_string($subject); 
     8  $message = mysql_real_escape_string($message); 
     9  $headers = mysql_real_escape_string($headers);   
    1010 
    1111  $query = "INSERT INTO o175453_general.mailer(recipient, subject, message, headers) VALUES('$to', '$subject', '$message', '$headers')"; 
Note: See TracChangeset for help on using the changeset viewer.