Plugin Directory

Changeset 570116


Ignore:
Timestamp:
07/10/2012 02:51:24 PM (14 years ago)
Author:
blazingtorch
Message:
 
Location:
paid-business-listings/trunk
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • paid-business-listings/trunk/inc/inc_display_form.php

    r490122 r570116  
    1616    //FORM VALIDATION
    1717    if($_POST['action']=="paypal_form"){
    18         $name=mysql_real_escape_string(stripslashes($_POST['pbl_listing_name']));
    19         $logo_url=mysql_real_escape_string(stripslashes($_POST['pbl_listing_logo_url']));
    20         $description=mysql_real_escape_string(stripslashes($_POST['pbl_listing_description']));
    21         $phone=mysql_real_escape_string(stripslashes($_POST['pbl_listing_phone']));
    22         $url=mysql_real_escape_string(stripslashes($_POST['pbl_listing_url']));
    23         $email=mysql_real_escape_string(stripslashes($_POST['pbl_listing_email']));
    24         $address=mysql_real_escape_string(stripslashes($_POST['pbl_listing_address']));
    25         $city=mysql_real_escape_string(stripslashes($_POST['pbl_listing_city']));
     18        $name=$_POST['pbl_listing_name'];
     19        $logo_url=$_POST['pbl_listing_logo_url'];
     20        $description=$_POST['pbl_listing_description'];
     21        $phone=$_POST['pbl_listing_phone'];
     22        $url=$_POST['pbl_listing_url'];
     23        $email=$_POST['pbl_listing_email'];
     24        $address=$_POST['pbl_listing_address'];
     25        $city=$_POST['pbl_listing_city'];
    2626        $state=$_POST['pbl_listing_state'];
    27         $zip=mysql_real_escape_string(stripslashes($_POST['pbl_listing_zip']));
     27        $zip=$_POST['pbl_listing_zip'];
    2828        $cat_id=$_POST['pbl_listing_cat_id'];
    2929        $pkg_id=$_POST['pbl_listing_pkg_id'];
     
    5252   
    5353        $wpdb->insert($wpdb->prefix.'pbl_listings',array('name'=>$name,'logo_url'=>$logo_url,'description'=>$description,'phone'=>$phone,'url'=>$url,'email'=>$email,'address'=>$address,'city'=>$city,'state'=>$state,'zip'=>$zip,'cat_id'=>$cat_id,'pkg_id'=>$pkg_id,'time_listed'=>$time_listed,'time_expired'=>$time_expired,'active'=>0));
    54            
     54                   
    5555        $package_info = $wpdb->get_row("SELECT id,name,cost,duration FROM ".$wpdb->prefix."pbl_packages WHERE id='$pkg_id'");
    5656        $submission_info = $wpdb->get_row("SELECT id FROM ".$wpdb->prefix."pbl_listings WHERE time_listed='$time_listed'");
  • paid-business-listings/trunk/inc/inc_pbl_edit_listing_page.php

    r501325 r570116  
    66    if($_POST['action']=="update_listing"){
    77        $id=$_POST['id'];
    8         $name=mysql_real_escape_string(stripslashes($_POST['pbl_listing_name']));
    9         $logo_url=mysql_real_escape_string(stripslashes($_POST['pbl_listing_logo_url']));
    10         $description=mysql_real_escape_string(stripslashes($_POST['pbl_listing_description']));
    11         $phone=mysql_real_escape_string(stripslashes($_POST['pbl_listing_phone']));
    12         $url=mysql_real_escape_string(stripslashes($_POST['pbl_listing_url']));
    13         $email=mysql_real_escape_string(stripslashes($_POST['pbl_listing_email']));
    14         $address=mysql_real_escape_string(stripslashes($_POST['pbl_listing_address']));
    15         $city=mysql_real_escape_string(stripslashes($_POST['pbl_listing_city']));
     8        $name=$_POST['pbl_listing_name'];
     9        $logo_url=$_POST['pbl_listing_logo_url'];
     10        $description=$_POST['pbl_listing_description'];
     11        $phone=$_POST['pbl_listing_phone'];
     12        $url=$_POST['pbl_listing_url'];
     13        $email=$_POST['pbl_listing_email'];
     14        $address=$_POST['pbl_listing_address'];
     15        $city=$_POST['pbl_listing_city'];
    1616        $state=$_POST['pbl_listing_state'];
    17         $zip=mysql_real_escape_string(stripslashes($_POST['pbl_listing_zip']));
     17        $zip=$_POST['pbl_listing_zip'];
    1818        $cat_id=$_POST['pbl_listing_cat_id'];
    1919        $pkg_id=$_POST['pbl_listing_pkg_id'];
     
    3030        }
    3131       
    32 
    3332        $wpdb->update($wpdb->prefix.'pbl_listings',array('name'=>$name,'logo_url'=>$logo_url,'description'=>$description,'phone'=>$phone,'url'=>$url,'email'=>$email,'address'=>$address,'city'=>$city,'state'=>$state,'zip'=>$zip,'cat_id'=>$cat_id,'pkg_id'=>$pkg_id,'time_listed'=>$time_listed,'time_expired'=>$time_expired),array('id'=>$id));
    3433   
  • paid-business-listings/trunk/inc/inc_thankyou_page_function.php

    r482498 r570116  
    99            $id=$_GET['subid'];
    1010            $wpdb->update($wpdb->prefix.'pbl_listings',array('active'=>1),array('id'=>$id));
     11           
    1112            $return.="<p>".get_option('pbl_thank_you_message')."</p>";
    1213        }else{
  • paid-business-listings/trunk/paid-business-listings.php

    r565156 r570116  
    44Plugin URI: http://www.paidbusinesslistings.com
    55Description: This is a plugin that allows businesses to add themselves to a category-based business listing directory on your Wordpress site using package parameters that you have set up.  Install the plugin, fill in your settings, and paste shortcode into WordPress pages or posts.
    6 Version: 1.0.2
     6Version: 1.0.3
    77Author: Bryan Haddock
    88Author URI: http://www.paidbusinesslistings.com/
  • paid-business-listings/trunk/readme.txt

    r565156 r570116  
    44Requires at least: 2.7
    55Tested up to: 3.4
    6 Stable tag: 1.0.2
     6Stable tag: 1.0.3
    77
    88Allow business to pay to add themselves to directory on your WordPress website
     
    7676* Fixed bug with MySQL syntax
    7777
     78= July 10, 2012 - 1.0.3 =
     79* Edited db queries for increased MySQL injection protection
Note: See TracChangeset for help on using the changeset viewer.