Revision 656
Added by thorn over 17 years ago
| save_post.php | ||
|---|---|---|
| 44 | 44 |
if($admin->get_post('title') == '' AND $admin->get_post('url') == '') {
|
| 45 | 45 |
$admin->print_error($MESSAGE['GENERIC']['FILL_IN_ALL'], WB_URL.'/modules/news/modify_post.php?page_id='.$page_id.'§ion_id='.$section_id.'&post_id='.$id); |
| 46 | 46 |
} else {
|
| 47 |
$title = $admin->add_slashes($admin->get_post('title'));
|
|
| 48 |
$short = $admin->add_slashes($admin->get_post('short'));
|
|
| 49 |
$long = $admin->add_slashes($admin->get_post('long'));
|
|
| 50 |
$commenting = $admin->get_post('commenting');
|
|
| 51 |
$active = $admin->get_post('active');
|
|
| 52 |
$old_link = $admin->get_post('link');
|
|
| 53 |
$group_id = $admin->get_post('group');
|
|
| 47 |
$title = $admin->get_post_escaped('title');
|
|
| 48 |
$short = $admin->get_post_escaped('short');
|
|
| 49 |
$long = $admin->get_post_escaped('long');
|
|
| 50 |
$commenting = $admin->get_post_escaped('commenting');
|
|
| 51 |
$active = $admin->get_post_escaped('active');
|
|
| 52 |
$old_link = $admin->get_post_escaped('link');
|
|
| 53 |
$group_id = $admin->get_post_escaped('group');
|
|
| 54 | 54 |
} |
| 55 | 55 |
|
| 56 | 56 |
// Get page link URL |
| ... | ... | |
| 103 | 103 |
} |
| 104 | 104 |
|
| 105 | 105 |
// get publisedwhen and publisheduntil |
| 106 |
$publishedwhen = jscalendar_to_timestamp($admin->get_post('publishdate'));
|
|
| 106 |
$publishedwhen = jscalendar_to_timestamp($admin->get_post_escaped('publishdate'));
|
|
| 107 | 107 |
if($publishedwhen == '' || $publishedwhen < 1) |
| 108 | 108 |
$publishedwhen=0; |
| 109 |
$publisheduntil = jscalendar_to_timestamp($admin->get_post('enddate'), $publishedwhen);
|
|
| 109 |
$publisheduntil = jscalendar_to_timestamp($admin->get_post_escaped('enddate'), $publishedwhen);
|
|
| 110 | 110 |
if($publisheduntil == '' || $publisheduntil < 1) |
| 111 | 111 |
$publisheduntil=0; |
| 112 | 112 |
|
Also available in: Unified diff
Added some missing add_slashes(), get_post_escaped(), and strip_tags() for $_POST, $_GET and $_REQUEST-data. Also for $_SERVER['PHP_SELF'].