Changeset 114
- Timestamp:
- 11/20/2007 04:27:02 PM (4 years ago)
- Location:
- trunk/www
- Files:
-
- 3 edited
-
htdocs/feedout.php (modified) (1 diff)
-
scripts/db2mail.php (modified) (1 diff)
-
scripts/mailer.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/www/htdocs/feedout.php
r113 r114 12 12 } 13 13 14 $name= mysql_real_escape_string($_POST['name']);14 $name=$_POST['name']; 15 15 checkOK($name); 16 $email= mysql_real_escape_string($_POST['email']);16 $email=$_POST['email']; 17 17 checkOK($email); 18 $comments= mysql_real_escape_string($_POST['comments']);18 $comments=$_POST['comments']; 19 19 //the checking of the comments is completly uneeded 20 20 //checkOK($comments); 21 21 22 $to= mysql_real_escape_string("openyahtzee-users@lists.sourceforge.net");22 $to="openyahtzee-users@lists.sourceforge.net"; 23 23 24 24 $message="The following feedback was sent to the list by $name <$email>.\n\n$comments"; -
trunk/www/scripts/db2mail.php
r113 r114 11 11 $total = 0; 12 12 while ($line = mysql_fetch_array($result, MYSQL_ASSOC)) { 13 $line['ID'] = stripcslashes($line['ID']);14 $line['subject'] = stripcslashe($line['subject']);15 $line['recipient'] = stripcslashe($line['recipient']);16 $line['headers'] = stripcslasheb($line['headers']);13 $line['ID'] = breakapart ($line['ID']); 14 $line['subject'] = breakapart($line['subject']); 15 $line['recipient'] = breakapart($line['recipient']); 16 $line['headers'] = breakapart($line['headers']); 17 17 $line['headers'] .= "Message-DBID: ". $line['ID'] ."\n"; 18 18 -
trunk/www/scripts/mailer.php
r74 r114 5 5 or die('Could not connect: ' . mysql_error()); 6 6 $to = addslashes($to); 7 $subject = addslashes($subject);8 $message = addslashes($message);9 $headers = addslashes($headers);7 $subject = mysql_real_escape_string($subject); 8 $message = mysql_real_escape_string($message); 9 $headers = mysql_real_escape_string($headers); 10 10 11 11 $query = "INSERT INTO o175453_general.mailer(recipient, subject, message, headers) VALUES('$to', '$subject', '$message', '$headers')";
Note: See TracChangeset
for help on using the changeset viewer.
