svn: web/php-bugs/trunk/ bug.php rpc.php

From: Date: Sun, 19 Jul 2009 23:19:40 +0000
Subject: svn: web/php-bugs/trunk/ bug.php rpc.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-5427@lists.php.net to get a copy of this message
rasmus Sun, 19 Jul 2009 23:19:40 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=284395 Changed paths: U web/php-bugs/trunk/bug.php U web/php-bugs/trunk/rpc.php Log: Revert the mysql escaping here. We are unfortunately relying on magic_quotes on this server. Hopefully the bug bug system will be ready soon. Modified: web/php-bugs/trunk/bug.php =================================================================== --- web/php-bugs/trunk/bug.php 2009-07-19 22:46:03 UTC (rev 284394) +++ web/php-bugs/trunk/bug.php 2009-07-19 23:19:40 UTC (rev 284395) @@ -124,7 +124,7 @@ if (!$errors) { $query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES" - . " ('$id','" . mysql_real_escape_string($in['commentemail']) . "',NOW(),'".mysql_real_escape_string($ncomment)."')"; + . " ('$id','{$in['commentemail']}',NOW(),'$ncomment')"; $success = @mysql_query($query); } $from = stripslashes($in['commentemail']); @@ -160,12 +160,12 @@ if (!$errors && !($errors = incoming_details_are_valid($in))) { /* update bug record */ - $query = "UPDATE bugdb SET sdesc='" . mysql_real_escape_string($in['sdesc']) . "',status='" . mysql_real_escape_string($in['status']) . "', bug_type='" . mysql_real_escape_string($in['bug_type']) . "', php_version='" . mysql_real_escape_string($in['php_version']) . "', php_os='" . mysql_real_escape_string($in['php_os']) . "', ts2=NOW(), email='".mysql_real_escape_string($from)."' WHERE id=$id"; + $query = "UPDATE bugdb SET sdesc='{$in['sdesc']}',status='{$in['status']}', bug_type='{$in['bug_type']}', php_version='{$in['php_version']}', php_os='{$in['php_os']}', ts2=NOW(), email='$from' WHERE id=$id"; $success = @mysql_query($query); /* add comment */ if ($success && !empty($ncomment)) { - $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'".mysql_real_escape_string($from)."',NOW(),'".mysql_real_escape_string($ncomment)."')"; + $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$from',NOW(),'$ncomment)')"; $success = @mysql_query($query); } } @@ -215,11 +215,11 @@ if (!$errors && !($errors = incoming_details_are_valid($in))) { $query = 'UPDATE bugdb SET '; - $query.= ($bug['email'] != $in['email'] && !empty($in['email'])) ? "email='" . mysql_real_escape_string($in['email']) . "', " : ''; - $query.= "sdesc='".mysql_real_escape_string($in[sdesc])."', status='".mysql_real_escape_string($in[status])."', bug_type='".mysql_real_escape_string($in[bug_type])."', assign='".mysql_real_escape_string($in[assign])."', php_version='".mysql_real_escape_string($in[php_version])."', php_os='".mysql_real_escape_string($in[php_os])."', ts2=NOW() WHERE id=$id"; + $query.= ($bug['email'] != $in['email'] && !empty($in['email'])) ? "email='{$in['email']}', " : ''; + $query.= "sdesc='{$in['sdesc']}', status='{$in['status']}', bug_type='{$in['bug_type']}', assign='{$in['assign']}', php_version='{$in['php_version']}', php_os='{$in['php_os']}', ts2=NOW() WHERE id=$id"; $success = @mysql_query($query); if ($success && !empty($ncomment)) { - $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$user@php.net',NOW(),'".mysql_real_escape_string($ncomment)."')"; + $query = "INSERT INTO bugdb_comments (bug, email, ts, comment) VALUES ($id,'$user@php.net',NOW(),'$ncomment')"; $success = @mysql_query($query); } Modified: web/php-bugs/trunk/rpc.php =================================================================== --- web/php-bugs/trunk/rpc.php 2009-07-19 22:46:03 UTC (rev 284394) +++ web/php-bugs/trunk/rpc.php 2009-07-19 23:19:40 UTC (rev 284395) @@ -46,7 +46,7 @@ if(!empty($_POST['ncomment'])) { $ncomment = trim($_POST['ncomment']); - $query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES ('$id','$user@php.net',NOW(),'".mysql_real_escape_string($ncomment)."')"; + $query = "INSERT INTO bugdb_comments (bug,email,ts,comment) VALUES ('$id','$user@php.net',NOW(),'$ncomment')"; $success = @mysql_query($query); if($success) { echo json_encode(array('result'=>array('status'=>$bug)));

« previous php.webmaster (#5427) next »