Changeset 11667
- Timestamp:
- 03/03/11 21:53:27 (2 years ago)
- Files:
-
- modules/branches/2.9/misdn/functions.inc.php (modified) (11 diffs)
- modules/branches/2.9/misdn/install.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
modules/branches/2.9/misdn/functions.inc.php
r11139 r11667 101 101 102 102 function misdn_general_get($key) { 103 $val = sql("SELECT `data` FROM `misdn` WHERE `keyword`='". mysql_escape_string($key)."' AND `id`='XXXXXX'", "getOne");103 $val = sql("SELECT `data` FROM `misdn` WHERE `keyword`='"._misdn_escape_string($key)."' AND `id`='XXXXXX'", "getOne"); 104 104 return $val; 105 105 } 106 106 107 107 function misdn_general_set($key, $val) { 108 sql("UPDATE `misdn` SET `data`='". mysql_escape_string($val)."' WHERE `keyword`='".mysql_escape_string($key)."' AND `id`='XXXXXX'");108 sql("UPDATE `misdn` SET `data`='"._misdn_escape_string($val)."' WHERE `keyword`='"._misdn_escape_string($key)."' AND `id`='XXXXXX'"); 109 109 } 110 110 … … 124 124 global $misdn_fields; 125 125 126 $ar = sql("SELECT name, type, $misdn_fields FROM `misdn_groups` WHERE `name` = '". mysql_escape_string($name)."'", "getAll", DB_FETCHMODE_ASSOC);126 $ar = sql("SELECT name, type, $misdn_fields FROM `misdn_groups` WHERE `name` = '"._misdn_escape_string($name)."'", "getAll", DB_FETCHMODE_ASSOC); 127 127 128 128 return array_shift($ar); … … 133 133 global $misdn_fields; 134 134 135 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` <> '". mysql_escape_string($name)."' ORDER BY `port` ASC", "getAll", DB_FETCHMODE_ASSOC);135 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` <> '"._misdn_escape_string($name)."' ORDER BY `port` ASC", "getAll", DB_FETCHMODE_ASSOC); 136 136 137 137 $ret = array(); … … 146 146 global $misdn_fields; 147 147 148 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` = '". mysql_escape_string($name)."' ORDER BY `port` ASC", "getAll", DB_FETCHMODE_ASSOC);148 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` = '"._misdn_escape_string($name)."' ORDER BY `port` ASC", "getAll", DB_FETCHMODE_ASSOC); 149 149 150 150 $ret = array(); … … 159 159 global $misdn_fields; 160 160 161 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` = '". mysql_escape_string($name)."'", "getAll", DB_FETCHMODE_ASSOC);161 $ar = sql("SELECT `port` FROM `misdn_ports` WHERE `group` = '"._misdn_escape_string($name)."'", "getAll", DB_FETCHMODE_ASSOC); 162 162 163 163 $ret = array(); … … 166 166 167 167 return $ret; 168 } 169 170 function _misdn_escape_string($var) { 171 global $db; 172 return $db->escapeSimple($var); 168 173 } 169 174 … … 356 361 return $v; 357 362 default: 358 return "'". mysql_escape_string($v)."'";363 return "'"._misdn_escape_string($v)."'"; 359 364 } 360 365 } … … 366 371 367 372 if ($_GET['del'] && $gdisplay) { 368 $name = mysql_escape_string($_GET['gdisplay']);373 $name = _misdn_escape_string($_GET['gdisplay']); 369 374 sql("DELETE FROM `misdn_ports` WHERE `group`='$name'"); 370 375 sql("DELETE FROM `misdn_groups` WHERE `name`='$name'"); … … 379 384 380 385 if ($_POST['editgroup']) { 381 $keyvals = array("`name`='". mysql_escape_string($_POST['name'])."'");386 $keyvals = array("`name`='"._misdn_escape_string($_POST['name'])."'"); 382 387 foreach($misdn_confkeys as $confkey) { 383 388 $keyvals[] = '`'.$confkey['name'].'`='.misdn_format_sql($confkey, $_POST[$confkey['name']]); 384 389 } 385 390 386 $sql = "UPDATE `misdn_groups` SET ".implode(',', $keyvals)." WHERE `name`='". mysql_escape_string($_POST['editgroup'])."'";387 sql("DELETE FROM `misdn_ports` WHERE `group`='". mysql_escape_string($_POST['editgroup'])."'");391 $sql = "UPDATE `misdn_groups` SET ".implode(',', $keyvals)." WHERE `name`='"._misdn_escape_string($_POST['editgroup'])."'"; 392 sql("DELETE FROM `misdn_ports` WHERE `group`='"._misdn_escape_string($_POST['editgroup'])."'"); 388 393 } 389 394 else { … … 398 403 settype($type, 'int'); 399 404 400 $sql = 'INSERT INTO `misdn_groups` (`name`,`type`,'.implode(',', $keys).") VALUES ('". mysql_escape_string($_POST['name'])."',$type,".implode(',', $vals).')';405 $sql = 'INSERT INTO `misdn_groups` (`name`,`type`,'.implode(',', $keys).") VALUES ('"._misdn_escape_string($_POST['name'])."',$type,".implode(',', $vals).')'; 401 406 } 402 407 … … 409 414 410 415 if ($_POST["port$i"]) 411 sql("INSERT INTO `misdn_ports` (`port`, `group`) VALUES ($i, '". mysql_escape_string($_POST['name'])."')");416 sql("INSERT INTO `misdn_ports` (`port`, `group`) VALUES ($i, '"._misdn_escape_string($_POST['name'])."')"); 412 417 } 413 418 } modules/branches/2.9/misdn/install.php
r11139 r11667 60 60 foreach(array_keys($groups) as $g) { 61 61 if (count($g)) { 62 sql('INSERT INTO `misdn_groups` (`name`,`type`,'.implode(',', $keys).") VALUES ('". mysql_escape_string($ptypes[$g]['name'])."',".$ptypes[$g]['type'].",".implode(',', $vals).')');62 sql('INSERT INTO `misdn_groups` (`name`,`type`,'.implode(',', $keys).") VALUES ('"._misdn_escape_string($ptypes[$g]['name'])."',".$ptypes[$g]['type'].",".implode(',', $vals).')'); 63 63 foreach($groups[$g] as $p) { 64 sql("INSERT INTO `misdn_ports` (`port`, `group`) VALUES ($p, '". mysql_escape_string($ptypes[$g]['name'])."')");64 sql("INSERT INTO `misdn_ports` (`port`, `group`) VALUES ($p, '"._misdn_escape_string($ptypes[$g]['name'])."')"); 65 65 } 66 66 }
