Skip to content

Commit c154cb4

Browse files
pagePage-
authored andcommitted
Query escaping and some formatting.
1 parent 2bb2609 commit c154cb4

File tree

137 files changed

+2596
-2748
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

137 files changed

+2596
-2748
lines changed

admin/Default/account_close.php

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
11
<?php
22
$close = $_REQUEST['close'];
33
if (isset($close)) {
4-
4+
55
//get accs to close
66
$reason = $_REQUEST['reason'];
77
//never expire
88
$expire_time = 0;
99
$amount = 0;
1010
foreach ($close as $key => $value) {
11-
11+
1212
$val = 'Match list:';
1313
$val .= $value;
1414
$bannedAccount =& SmrAccount::getAccount($key);
1515
$bannedAccount->banAccount($expire_time,$account,2,$val);
1616
$amount++;
1717
}
18-
18+
1919
}
2020
$first = $_REQUEST['first'];
2121
if (isset($first)) {
@@ -76,7 +76,7 @@
7676
$reason = $suspicion[$id];
7777
if (empty($reason) || $reason == '')
7878
$reason = $suspicion2[$id];
79-
$db->query('SELECT * FROM account_is_closed WHERE account_id = '.$id);
79+
$db->query('SELECT * FROM account_is_closed WHERE account_id = '.$db->escapeNumber($id));
8080
if (!$db->getNumRows())
8181
$amount += 1;
8282

admin/Default/account_edit.php

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@
7373

7474
if ($curr_account!==false) {
7575
$editingPlayers = array();
76-
$db->query('SELECT game_id FROM player WHERE account_id = ' . $curr_account->getAccountID() . ' ORDER BY game_id ASC');
76+
$db->query('SELECT game_id FROM player WHERE account_id = ' . $db->escapeNumber($curr_account->getAccountID()) . ' ORDER BY game_id ASC');
7777
while ($db->nextRecord()) {
7878
$editingPlayers[] =& SmrPlayer::getPlayer($curr_account->getAccountID(), $db->getInt('game_id'));
7979
}
@@ -89,9 +89,9 @@
8989
$banReasons[$db->getInt('reason_id')] = $reason;
9090
}
9191
$template->assign('BanReasons', $banReasons);
92-
92+
9393
$closingHistory = array();
94-
$db->query('SELECT * FROM account_has_closing_history WHERE account_id = ' . $curr_account->getAccountID() . ' ORDER BY time DESC');
94+
$db->query('SELECT * FROM account_has_closing_history WHERE account_id = ' . $db->escapeNumber($curr_account->getAccountID()) . ' ORDER BY time DESC');
9595
while ($db->nextRecord()) {
9696
// if an admin did it we get his/her name
9797
if ($admin_id > 0) {
@@ -114,7 +114,7 @@
114114
}
115115

116116
$recentIPs = array();
117-
$db->query('SELECT ip, time, host FROM account_has_ip WHERE account_id = ' . $curr_account->getAccountID() . ' ORDER BY time DESC');
117+
$db->query('SELECT ip, time, host FROM account_has_ip WHERE account_id = ' . $db->escapeNumber($curr_account->getAccountID()) . ' ORDER BY time DESC');
118118
while ($db->nextRecord()) {
119119
$recentIPs[] = array(
120120
'IP' => $db->getField('ip'),

admin/Default/account_edit_processing.php

Lines changed: 95 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
if (!empty($donation))
2424
{
2525
// add entry to account donated table
26-
$db->query('INSERT INTO account_donated (account_id, time, amount) VALUES ('.$account_id.', ' . TIME . ' , '.$donation.')');
26+
$db->query('INSERT INTO account_donated (account_id, time, amount) VALUES ('.$db->escapeNumber($account_id).', ' . $db->escapeNumber(TIME) . ' , '.$db->escapeNumber($donation).')');
2727

2828
// add the credits to the players account - if requested
2929
if (!empty($smr_credit))
@@ -80,7 +80,7 @@
8080
$msg .= 'and ';
8181
$msg .= 'mail banned ';
8282
}
83-
83+
8484
if($points > 0 && ($bannedDays = $curr_account->addPoints($points,$account,$reason_id,$_REQUEST['suspicion']))!==false)
8585
{
8686
if ($bannedDays > 0)
@@ -95,7 +95,7 @@
9595

9696
if ($veteran_status != $curr_account->isVeteranBumped()) {
9797

98-
$db->query('UPDATE account SET veteran = '.$db->escapeString($veteran_status).' WHERE account_id = '.$account_id);
98+
$db->query('UPDATE account SET veteran = '.$db->escapeString($veteran_status).' WHERE account_id = '.$db->escapeNumber($account_id));
9999
$msg .= 'set the veteran status to '.$db->escapeString($veteran_status).' ';
100100

101101
}
@@ -107,7 +107,7 @@
107107
}
108108
if ($except != 'Add An Exception' && $except != '') {
109109

110-
$db->query('INSERT INTO account_exceptions (account_id, reason) VALUES ('.$account_id.', '.$db->escapeString($except).')');
110+
$db->query('INSERT INTO account_exceptions (account_id, reason) VALUES ('.$db->escapeNumber($account_id).', '.$db->escapeString($except).')');
111111
$msg .= 'added the exception '.$except.' ';
112112

113113
}
@@ -117,84 +117,123 @@
117117
{
118118
if(!empty($new_name))
119119
{
120-
$db->query('SELECT * FROM player WHERE game_id = '.$game_id.' AND player_name = ' . $db->escape_string($new_name, FALSE));
120+
$db->query('SELECT * FROM player WHERE game_id = '.$db->escapeNumber($game_id).' AND player_name = ' . $db->escape_string($new_name, FALSE));
121121
if (!$db->nextRecord()) {
122-
$db->query('SELECT player_name, player_id FROM player WHERE game_id='.$game_id.' AND account_id = '.$account_id.' LIMIT 1');
122+
$db->query('SELECT player_name, player_id FROM player WHERE game_id='.$db->escapeNumber($game_id).' AND account_id = '.$db->escapeNumber($account_id).' LIMIT 1');
123123
$db->nextRecord();
124124
$old_name = $db->getField('player_name');
125-
$player_id = $db->getField('player_id');
126-
127-
$db->query('UPDATE player SET player_name = ' . $db->escape_string($new_name, FALSE) . ' WHERE game_id = '.$game_id.' AND account_id = '.$account_id);
125+
$player_id = $db->getInt('player_id');
126+
127+
$db->query('UPDATE player SET player_name = ' . $db->escape_string($new_name, FALSE) . ' WHERE game_id = '.$db->escapeNumber($game_id).' AND account_id = '.$db->escapeNumber($account_id));
128128
$msg .= 'changed players name to '.$new_name.' ';
129129
//insert news message
130-
130+
131131
$news = '<span class="blue">ADMIN</span> Please be advised that <span class="yellow">' . $old_name . '(' . $player_id . ')</span> has had their name changed to <span class="yellow">' . $new_name . '(' . $player_id . ')</span>';
132-
133-
$db->query('INSERT INTO news (time, news_message, game_id) VALUES (' . TIME . ',' . $db->escape_string($news, FALSE) . ','.$game_id.')');
132+
133+
$db->query('INSERT INTO news (time, news_message, game_id) VALUES (' . $db->escapeNumber(TIME) . ',' . $db->escape_string($news, FALSE) . ','.$db->escapeNumber($game_id).')');
134134
}
135135
}
136-
136+
137137
}
138138

139139
if (!empty($delete)) {
140140
foreach ($delete as $game_id => $value) {
141141
if($value == 'TRUE') {
142142
// Check for bank transactions into the alliance account
143-
$db->query('SELECT * FROM alliance_bank_transactions WHERE payee_id=' . $account_id . ' AND game_id=' . $game_id . ' LIMIT 1');
143+
$db->query('SELECT * FROM alliance_bank_transactions WHERE payee_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id) . ' LIMIT 1');
144144
if($db->getNumRows() != 0){
145145
// Can't delete
146146
$msg .= 'player has made alliance transaction ';
147147
continue;
148148
}
149149
// Check anon accounts for transactions
150-
$db->query('SELECT * FROM anon_bank_transactions WHERE account_id=' . $account_id . ' AND game_id=' . $game_id . ' LIMIT 1');
150+
$db->query('SELECT * FROM anon_bank_transactions WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id) . ' LIMIT 1');
151151
if($db->getNumRows() != 0){
152152
// Can't delete
153153
$msg .= 'player has made anonymous transaction ';
154154
continue;
155155
}
156156

157-
$db->query('DELETE FROM alliance_thread WHERE sender_id=' . $account_id . ' AND game_id=' . $game_id);
158-
$db->query('DELETE FROM blackjack WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
159-
$db->query('DELETE FROM bounty WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
160-
$db->query('DELETE FROM force_refresh WHERE owner_id=' . $account_id . ' AND game_id=' . $game_id);
161-
$db->query('DELETE FROM galactic_post_applications WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
162-
$db->query('DELETE FROM galactic_post_article WHERE writer_id=' . $account_id . ' AND game_id=' . $game_id);
163-
$db->query('DELETE FROM galactic_post_writer WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
164-
$db->query('DELETE FROM kills WHERE (dead_id=' . $account_id . ' OR killer_id=' . $account_id .') AND game_id=' . $game_id);
165-
$db->query('DELETE FROM message WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
166-
$db->query('DELETE FROM message_notify WHERE (from_id=' . $account_id . ' OR to_id=' . $account_id .') AND game_id=' . $game_id);
167-
$db->query('DELETE FROM message WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
168-
$db->query('UPDATE planet SET owner_id=0,planet_name=\'\',password=\'\',shields=0,drones=0,credits=0,bonds=0 WHERE owner_id=' . $account_id . ' AND game_id=' . $game_id);
169-
$db->query('DELETE FROM planet_attack WHERE trigger_id=' . $account_id . ' AND game_id=' . $game_id);
170-
$db->query('DELETE FROM player_attacks_planet WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
171-
$db->query('DELETE FROM player_attacks_port WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
172-
$db->query('DELETE FROM player_cache WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
173-
$db->query('DELETE FROM player_has_alliance_role WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
174-
$db->query('DELETE FROM player_has_drinks WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
175-
$db->query('DELETE FROM player_has_relation WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
176-
$db->query('DELETE FROM player_has_ticker WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
177-
$db->query('DELETE FROM player_has_ticket WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
178-
$db->query('DELETE FROM player_has_unread_messages WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
179-
$db->query('DELETE FROM player_is_president WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
180-
$db->query('DELETE FROM player_plotted_course WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
181-
$db->query('DELETE FROM player_read_thread WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
182-
$db->query('DELETE FROM player_visited_port WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
183-
$db->query('DELETE FROM player_visited_sector WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
184-
$db->query('DELETE FROM player_votes_pact WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
185-
$db->query('DELETE FROM player_votes_relation WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
186-
$db->query('DELETE FROM ship_has_cargo WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
187-
$db->query('DELETE FROM ship_has_hardware WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
188-
$db->query('DELETE FROM ship_has_illusion WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
189-
$db->query('DELETE FROM ship_has_name WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
190-
$db->query('DELETE FROM ship_has_weapon WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
191-
$db->query('DELETE FROM ship_is_cloaked WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
192-
$db->query('DELETE FROM player WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
193-
$db->query('DELETE FROM player_has_stats WHERE account_id=' . $account_id . ' AND game_id=' . $game_id);
194-
195-
$db->query('UPDATE account_has_stats SET games_joined=games_joined-1 WHERE account_id=' . $account_id);
196-
197-
$db->query('UPDATE active_session SET game_id=0 WHERE account_id=' . $account_id . ' AND game_id=' . $game_id .' LIMIT 1');
157+
$db->query('DELETE FROM alliance_thread
158+
WHERE sender_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
159+
$db->query('DELETE FROM blackjack
160+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
161+
$db->query('DELETE FROM bounty
162+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
163+
$db->query('DELETE FROM force_refresh
164+
WHERE owner_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
165+
$db->query('DELETE FROM galactic_post_applications
166+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
167+
$db->query('DELETE FROM galactic_post_article
168+
WHERE writer_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
169+
$db->query('DELETE FROM galactic_post_writer
170+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
171+
$db->query('DELETE FROM kills
172+
WHERE (dead_id=' . $db->escapeNumber($account_id) . ' OR killer_id=' . $db->escapeNumber($account_id) .') AND game_id=' . $db->escapeNumber($game_id));
173+
$db->query('DELETE FROM message
174+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
175+
$db->query('DELETE FROM message_notify
176+
WHERE (from_id=' . $db->escapeNumber($account_id) . ' OR to_id=' . $db->escapeNumber($account_id) .') AND game_id=' . $db->escapeNumber($game_id));
177+
$db->query('DELETE FROM message
178+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
179+
$db->query('UPDATE planet SET owner_id=0,planet_name=\'\',password=\'\',shields=0,drones=0,credits=0,bonds=0
180+
WHERE owner_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
181+
$db->query('DELETE FROM planet_attack
182+
WHERE trigger_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
183+
$db->query('DELETE FROM player_attacks_planet
184+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
185+
$db->query('DELETE FROM player_attacks_port
186+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
187+
$db->query('DELETE FROM player_cache
188+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
189+
$db->query('DELETE FROM player_has_alliance_role
190+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
191+
$db->query('DELETE FROM player_has_drinks
192+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
193+
$db->query('DELETE FROM player_has_relation
194+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
195+
$db->query('DELETE FROM player_has_ticker
196+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
197+
$db->query('DELETE FROM player_has_ticket
198+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
199+
$db->query('DELETE FROM player_has_unread_messages
200+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
201+
$db->query('DELETE FROM player_is_president
202+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
203+
$db->query('DELETE FROM player_plotted_course
204+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
205+
$db->query('DELETE FROM player_read_thread
206+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
207+
$db->query('DELETE FROM player_visited_port
208+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
209+
$db->query('DELETE FROM player_visited_sector
210+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
211+
$db->query('DELETE FROM player_votes_pact
212+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
213+
$db->query('DELETE FROM player_votes_relation
214+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
215+
$db->query('DELETE FROM ship_has_cargo
216+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
217+
$db->query('DELETE FROM ship_has_hardware
218+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
219+
$db->query('DELETE FROM ship_has_illusion
220+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
221+
$db->query('DELETE FROM ship_has_name
222+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
223+
$db->query('DELETE FROM ship_has_weapon
224+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
225+
$db->query('DELETE FROM ship_is_cloaked
226+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
227+
$db->query('DELETE FROM player
228+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
229+
$db->query('DELETE FROM player_has_stats
230+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id));
231+
232+
$db->query('UPDATE account_has_stats SET games_joined=games_joined-1
233+
WHERE account_id=' . $db->escapeNumber($account_id));
234+
235+
$db->query('UPDATE active_session SET game_id=0
236+
WHERE account_id=' . $db->escapeNumber($account_id) . ' AND game_id=' . $db->escapeNumber($game_id) .' LIMIT 1');
198237

199238
$msg .= 'deleted player from game '.$game_id.' ';
200239
}

admin/Default/account_ip_view_result.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@
6262

6363
$new_acc =& SmrAccount::getAccount($account_wanted);
6464
$last_acc =& SmrAccount::getAccount($last_acc_id);
65-
$db2->query('SELECT * FROM account_is_closed WHERE account_id = '.$acc_id);
65+
$db2->query('SELECT * FROM account_is_closed WHERE account_id = '.$db2->escapeNumber($acc_id));
6666
if ($db2->getNumRows() && $db_ip != $last_ip) continue;
6767
$PHP_OUTPUT.=('<tr>');
6868
$PHP_OUTPUT.=('<td align=center>'.$new_acc->getLogin().' ('.$new_acc->getAccountID().')</td>');

admin/Default/admin_message_send.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
if ($gameID != 20000)
2222
{
2323
$gamePlayers = array();
24-
$db->query('SELECT account_id,player_id,player_name FROM player WHERE game_id = '.$gameID.' ORDER BY player_name');
24+
$db->query('SELECT account_id,player_id,player_name FROM player WHERE game_id = '.$db->escapeNumber($gameID).' ORDER BY player_name');
2525
while ($db->nextRecord())
2626
$gamePlayers[]= array('AccountID' => $db->getField('account_id'), 'PlayerID' => $db->getField('player_id'), 'Name' => $db->getField('player_name'));
2727
$template->assignByRef('GamePlayers',$gamePlayers);

admin/Default/album_approve_processing.php

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
11
<?php
22

3-
if ($_POST['action'] == 'Approve')
3+
if ($_REQUEST['action'] == 'Approve') {
44
$approved = 'YES';
5-
else
5+
}
6+
else {
67
$approved = 'NO';
8+
}
79

810
$db->query('UPDATE album
911
SET approved = '.$db->escapeString($approved).'
10-
WHERE account_id = ' . $var['album_id']);
12+
WHERE account_id = ' . $db->escapeNumber($var['album_id']));
1113

1214
forward(create_container('skeleton.php', 'album_approve.php'));
1315

admin/Default/album_moderate.php

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@
3030
// check if the givin account really has an entry
3131
if ($account_id > 0)
3232
{
33-
$db->query('SELECT * FROM album WHERE account_id = '.$account_id.' AND Approved = \'YES\'');
33+
$db->query('SELECT * FROM album WHERE account_id = '.$db->escapeNumber($account_id).' AND Approved = \'YES\'');
3434
if ($db->nextRecord())
3535
{
3636
$disabled = $db->getBoolean('disabled');
@@ -157,12 +157,12 @@
157157

158158
$db->query('SELECT *
159159
FROM album_has_comments
160-
WHERE album_id = '.$account_id);
160+
WHERE album_id = '.$db->escapeNumber($account_id));
161161
while ($db->nextRecord())
162162
{
163-
$comment_id = $db->getField('comment_id');
164-
$time = $db->getField('time');
165-
$postee = get_album_nick($db->getField('post_id'));
163+
$comment_id = $db->getInt('comment_id');
164+
$time = $db->getInt('time');
165+
$postee = get_album_nick($db->getInt('post_id'));
166166
$msg = stripslashes($db->getField('msg'));
167167

168168
$PHP_OUTPUT.=('<tr><td align="center"><input type="checkbox" name="comment_ids[]" value="'.$comment_id.'"></td><td colspan="3"><span style="font-size:85%;">[' . date('Y/n/j g:i A', $time) . '] &lt;'.$postee.'&gt; '.$msg.'</span></td></tr>');

0 commit comments

Comments
 (0)