diff --git a/www/disputes.php b/www/disputes.php index 045277f..4c9c56f 100644 --- a/www/disputes.php +++ b/www/disputes.php @@ -311,6 +311,7 @@ } unset($oldid); $query = "select * from `domains` where `domain`='$domain' and `deleted`=0"; + $email = trim(mysql_real_escape_string($_REQUEST['email'])); $res = mysql_query($query); if(mysql_num_rows($res) <= 0) { @@ -331,7 +332,7 @@ $domainid = $row['id']; $_SESSION['_config']['domainid'] = $domainid; - $_SESSION['_config']['memid'] = $memid; + $_SESSION['_config']['memid'] = intval($_REQUEST['memid']); $_SESSION['_config']['domain'] = $domain; $_SESSION['_config']['oldmemid'] = $oldmemid; @@ -381,7 +382,7 @@ if($oldid == "5") { - $authaddy = trim(mysql_escape_string(stripslashes($_POST['authaddy']))); + $authaddy = trim(mysql_escape_string(stripslashes($_REQUEST['authaddy']))); if(!in_array($authaddy, $_SESSION['_config']['addy']) || $authaddy == "") {