Changeset 251 for quests/save.php


Ignore:
Timestamp:
Jan 20, 2008, 8:44:37 PM (17 years ago)
Author:
maron
Message:

NPC_text

File:
1 edited

Legend:

Unmodified
Added
Removed
  • quests/save.php

    r247 r251  
    22
    33  include('includes/global.php');
     4
     5  // SQL injection hack protection
     6  foreach($_POST as $Index => $Item) $_POST[$Index] = addslashes($Item);
     7  foreach($_GET as $Index => $Item) $_GET[$Index] = addslashes($Item);
    48
    59  if (array_key_exists('entry', $_POST)) {
     
    3943    if (!$Line) {
    4044   
    41       $Database->SQLCommand("INSERT INTO `quests` (`entry` , `Title` , `Details` , `Objectives` , `OfferRewardText` , `RequestItemsText` , `EndText` , `ObjectiveText1` , `ObjectiveText2` , `ObjectiveText3` , `ObjectiveText4` , `Language` , `User` , `complete` , `Take` )
    42       VALUES('$entry','$Title','$Details','$Objectives','$OfferRewardText','$RequestItemsText','$EndText','$ObjectiveText1','$ObjectiveText2','$ObjectiveText3','$ObjectiveText4','$Language','$UserID','$complete','$QuestID')");
     45      $Database->SQLCommand("INSERT INTO `quests` (`entry` , `Title` , `Details` , `Objectives` , `OfferRewardText` , `RequestItemsText` ,
     46      `EndText` , `ObjectiveText1` , `ObjectiveText2` , `ObjectiveText3` , `ObjectiveText4` , `Language` , `User` , `complete` , `Take` , `Vote` , `CountVote` )
     47      VALUES('$entry','$Title','$Details','$Objectives','$OfferRewardText','$RequestItemsText','$EndText','$ObjectiveText1',
     48      '$ObjectiveText2','$ObjectiveText3','$ObjectiveText4','$Language','$UserID','$complete','$QuestID','3','1')");
    4349      echo 'Quest: '.$entry.' ulo¾en!<br />';
    44       WriteLog('Quest: '.$entry.' ulo¾en! <a href="form.php?ID='.$QuestID.'">'.$QuestID.'</a>', 1);
     50      WriteLog('Quest: '.$entry.' uloµen! <a href="form.php?ID='.$QuestID.'">'.$QuestID.'</a>', 1);
    4551    } else {
    4652      $sql = "UPDATE quests SET complete = '$complete', Title = '$Title',
     
    5460    //  echo $sql.'<br />';     
    5561      echo 'Zmìny v Questu: '.$entry.' ulo¾eny!<br />';
    56       WriteLog('Zmìny v Questu: '.$entry.' ulo¾eny! <a href="form.php?ID='.$QuestID.'">'.$QuestID.'</a>', 1);
     62      WriteLog('Zmìny v Questu: '.$entry.' uloµeny! <a href="form.php?ID='.$QuestID.'">'.$QuestID.'</a>', 1);
    5763      $Database->SQLCommand("DELETE FROM `quests_vote` WHERE `quests_vote`.`IDquest` = ".$QuestID);
    5864    }
    5965   
    60     echo 'Pøekládat: <a href="ListQuests.php?selection">Nepøeloµené</a> ';
     66    echo 'Pøekládat: <a href="ListQuests.php?selection">Nepøeloœené</a> ';
    6167     
    6268  }
Note: See TracChangeset for help on using the changeset viewer.