Improved parameter checking

This commit is contained in:
root 2008-08-15 22:55:17 +00:00
parent a71504fc3a
commit ae56e3ca62

View file

@ -53,7 +53,7 @@
$password = mysql_escape_string(stripslashes(trim($_REQUEST["pword"]))); $password = mysql_escape_string(stripslashes(trim($_REQUEST["pword"])));
$URL = mysql_escape_string(trim($_REQUEST["notaryURL"])); $URL = mysql_escape_string(trim($_REQUEST["notaryURL"]));
$CN = mysql_escape_string($_SESSION['_config']['CN']); $CN = mysql_escape_string($_SESSION['_config']['CN']);
$memid = mysql_escape_string($_SESSION['_config']['uid']); $memid = intval($_SESSION['_config']['uid']);
$user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='$memid'")); $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='$memid'"));
$tmp = mysql_fetch_assoc(mysql_query("select sum(`points`) as `points` from `notary` where `to`='$memid'")); $tmp = mysql_fetch_assoc(mysql_query("select sum(`points`) as `points` from `notary` where `to`='$memid'"));