Added XSS protection

Tagged texts for translation
pull/1/head
root 16 years ago
parent 88d64278b9
commit 5e5df87d2e

@ -31,7 +31,7 @@
{
$reg = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'"));
$display = "<ul class='top'>\n<li>\n".
"<a href='account.php?id=53&amp;regid=$regid'>$reg[name]</a> - <a href='account.php?action=add&amp;id=54&amp;regid=$regid'>Add</a>\n".
"<a href='account.php?id=53&amp;regid=$regid'>".sanitizeHTML($reg[name])."</a> - <a href='account.php?action=add&amp;id=54&amp;regid=$regid'>"._("Add")."</a>\n".
$display;
$ccid = $_REQUEST['ccid'] = intval($reg['ccid']);
}
@ -40,7 +40,7 @@
{
$cnt = mysql_fetch_assoc(mysql_query("select * from `countries` where `id`='$ccid'"));
$display = "<ul class='top'>\n<li>\n".
"<a href='account.php?id=53&amp;ccid=$ccid'>$cnt[name]</a> - <a href='account.php?action=add&amp;id=54&amp;ccid=$ccid'>Add</a>\n".
"<a href='account.php?id=53&amp;ccid=$ccid'>".sanitizeHTML($cnt[name])."</a> - <a href='account.php?action=add&amp;id=54&amp;ccid=$ccid'>"._("Add")."</a>\n".
$display;
}
@ -62,9 +62,9 @@
$res = mysql_query($query);
while($row = mysql_fetch_assoc($res))
{
echo "<li>( <a href='account.php?action=edit&amp;id=54&regid=".intval($row['id'])."'>edit</a> |";
echo "<li>( <a href='account.php?action=edit&amp;id=54&regid=".intval($row['id'])."'>"._("edit")."</a> |";
echo " <a href='account.php?action=delete&amp;id=53&regid=".intval($row['id'])."'";
echo " onclick=\"return confirm('Are you sure you want to delete this region and all connected locations?');\">delete</a> )";
echo " onclick=\"return confirm('"._("Are you sure you want to delete this region and all connected locations?")."');\">"._("delete")."</a> )";
echo " <a href='account.php?id=53&amp;regid=".intval($row['id'])."'>".sanitizeHTML($row['name'])."</a></li>\n";
}
@ -80,11 +80,11 @@
$res = mysql_query($query);
while($row = mysql_fetch_assoc($res))
{
echo "<li>( <a href='account.php?action=move&amp;id=54&amp;locid=".intval($row['id'])."'>move</a> |";
echo " <a href='account.php?action=aliases&amp;id=54&amp;locid=".intval($row['id'])."'>aliases</a> |";
echo " <a href='account.php?action=edit&amp;id=54&amp;locid=".intval($row['id'])."'>edit</a> |";
echo "<li>( <a href='account.php?action=move&amp;id=54&amp;locid=".intval($row['id'])."'>"._("move")."</a> |";
echo " <a href='account.php?action=aliases&amp;id=54&amp;locid=".intval($row['id'])."'>"._("aliases")."</a> |";
echo " <a href='account.php?action=edit&amp;id=54&amp;locid=".intval($row['id'])."'>"._("edit")."</a> |";
echo " <a href='account.php?action=delete&amp;id=53&amp;locid=".intval($row['id'])."'";
echo " onclick=\"return confirm('Are you sure you want to delete this location?');\">delete</a> ) ".sanitizeHTML($row['name'])." (".sanitizeHTML($row['lat']).",".sanitizeHTML($row['long']).")</li>\n";
echo " onclick=\"return confirm('Are you sure you want to delete this location?');\">"._("delete")."</a> ) ".sanitizeHTML($row['name'])." (".sanitizeHTML($row['lat']).",".sanitizeHTML($row['long']).")</li>\n";
}
echo "</ul>\n</li>\n</ul>\n</li>\n</ul></div>\n<br>\n";
@ -96,16 +96,16 @@
if($prev < 0)
$prev = 0;
$st = "[ <a href='account.php?id=53&amp;regid=$regid'><< Start</a> ] ";
$prev = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$prev'>< Previous $limit</a> ] ";
$st = "[ <a href='account.php?id=53&amp;regid=$regid'><< "._("Start")."</a> ] ";
$prev = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$prev'>< "._("Previous")." $limit</a> ] ";
}
if($start < $rc - $limit)
{
$next = $start + $limit;
$last = $rc - $limit;
$next = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$next'>Next $limit ></a> ] ";
$end = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$last'>End >></a> ]";
$next = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$next'>"._("Next")." $limit ></a> ] ";
$end = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$last'>"._("End")." >></a> ]";
}
echo "<div id='search1'>$st</div><div id='search3'>$end</div>\n";
echo "<div id='search2'>$prev</div><div id='search4'>$next</div>\n";

Loading…
Cancel
Save