Added XSS protection

Tagged texts for translation
pull/1/head
root 16 years ago
parent 88d64278b9
commit 5e5df87d2e

@ -31,7 +31,7 @@
{ {
$reg = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'")); $reg = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'"));
$display = "<ul class='top'>\n<li>\n". $display = "<ul class='top'>\n<li>\n".
"<a href='account.php?id=53&amp;regid=$regid'>$reg[name]</a> - <a href='account.php?action=add&amp;id=54&amp;regid=$regid'>Add</a>\n". "<a href='account.php?id=53&amp;regid=$regid'>".sanitizeHTML($reg[name])."</a> - <a href='account.php?action=add&amp;id=54&amp;regid=$regid'>"._("Add")."</a>\n".
$display; $display;
$ccid = $_REQUEST['ccid'] = intval($reg['ccid']); $ccid = $_REQUEST['ccid'] = intval($reg['ccid']);
} }
@ -40,7 +40,7 @@
{ {
$cnt = mysql_fetch_assoc(mysql_query("select * from `countries` where `id`='$ccid'")); $cnt = mysql_fetch_assoc(mysql_query("select * from `countries` where `id`='$ccid'"));
$display = "<ul class='top'>\n<li>\n". $display = "<ul class='top'>\n<li>\n".
"<a href='account.php?id=53&amp;ccid=$ccid'>$cnt[name]</a> - <a href='account.php?action=add&amp;id=54&amp;ccid=$ccid'>Add</a>\n". "<a href='account.php?id=53&amp;ccid=$ccid'>".sanitizeHTML($cnt[name])."</a> - <a href='account.php?action=add&amp;id=54&amp;ccid=$ccid'>"._("Add")."</a>\n".
$display; $display;
} }
@ -62,9 +62,9 @@
$res = mysql_query($query); $res = mysql_query($query);
while($row = mysql_fetch_assoc($res)) while($row = mysql_fetch_assoc($res))
{ {
echo "<li>( <a href='account.php?action=edit&amp;id=54&regid=".intval($row['id'])."'>edit</a> |"; echo "<li>( <a href='account.php?action=edit&amp;id=54&regid=".intval($row['id'])."'>"._("edit")."</a> |";
echo " <a href='account.php?action=delete&amp;id=53&regid=".intval($row['id'])."'"; echo " <a href='account.php?action=delete&amp;id=53&regid=".intval($row['id'])."'";
echo " onclick=\"return confirm('Are you sure you want to delete this region and all connected locations?');\">delete</a> )"; echo " onclick=\"return confirm('"._("Are you sure you want to delete this region and all connected locations?")."');\">"._("delete")."</a> )";
echo " <a href='account.php?id=53&amp;regid=".intval($row['id'])."'>".sanitizeHTML($row['name'])."</a></li>\n"; echo " <a href='account.php?id=53&amp;regid=".intval($row['id'])."'>".sanitizeHTML($row['name'])."</a></li>\n";
} }
@ -80,11 +80,11 @@
$res = mysql_query($query); $res = mysql_query($query);
while($row = mysql_fetch_assoc($res)) while($row = mysql_fetch_assoc($res))
{ {
echo "<li>( <a href='account.php?action=move&amp;id=54&amp;locid=".intval($row['id'])."'>move</a> |"; echo "<li>( <a href='account.php?action=move&amp;id=54&amp;locid=".intval($row['id'])."'>"._("move")."</a> |";
echo " <a href='account.php?action=aliases&amp;id=54&amp;locid=".intval($row['id'])."'>aliases</a> |"; echo " <a href='account.php?action=aliases&amp;id=54&amp;locid=".intval($row['id'])."'>"._("aliases")."</a> |";
echo " <a href='account.php?action=edit&amp;id=54&amp;locid=".intval($row['id'])."'>edit</a> |"; echo " <a href='account.php?action=edit&amp;id=54&amp;locid=".intval($row['id'])."'>"._("edit")."</a> |";
echo " <a href='account.php?action=delete&amp;id=53&amp;locid=".intval($row['id'])."'"; echo " <a href='account.php?action=delete&amp;id=53&amp;locid=".intval($row['id'])."'";
echo " onclick=\"return confirm('Are you sure you want to delete this location?');\">delete</a> ) ".sanitizeHTML($row['name'])." (".sanitizeHTML($row['lat']).",".sanitizeHTML($row['long']).")</li>\n"; echo " onclick=\"return confirm('Are you sure you want to delete this location?');\">"._("delete")."</a> ) ".sanitizeHTML($row['name'])." (".sanitizeHTML($row['lat']).",".sanitizeHTML($row['long']).")</li>\n";
} }
echo "</ul>\n</li>\n</ul>\n</li>\n</ul></div>\n<br>\n"; echo "</ul>\n</li>\n</ul>\n</li>\n</ul></div>\n<br>\n";
@ -96,16 +96,16 @@
if($prev < 0) if($prev < 0)
$prev = 0; $prev = 0;
$st = "[ <a href='account.php?id=53&amp;regid=$regid'><< Start</a> ] "; $st = "[ <a href='account.php?id=53&amp;regid=$regid'><< "._("Start")."</a> ] ";
$prev = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$prev'>< Previous $limit</a> ] "; $prev = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$prev'>< "._("Previous")." $limit</a> ] ";
} }
if($start < $rc - $limit) if($start < $rc - $limit)
{ {
$next = $start + $limit; $next = $start + $limit;
$last = $rc - $limit; $last = $rc - $limit;
$next = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$next'>Next $limit ></a> ] "; $next = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$next'>"._("Next")." $limit ></a> ] ";
$end = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$last'>End >></a> ]"; $end = "[ <a href='account.php?id=53&amp;regid=$regid&amp;start=$last'>"._("End")." >></a> ]";
} }
echo "<div id='search1'>$st</div><div id='search3'>$end</div>\n"; echo "<div id='search1'>$st</div><div id='search3'>$end</div>\n";
echo "<div id='search2'>$prev</div><div id='search4'>$next</div>\n"; echo "<div id='search2'>$prev</div><div id='search4'>$next</div>\n";

Loading…
Cancel
Save