Plugin Directory

Changeset 1047338


Ignore:
Timestamp:
12/17/2014 06:14:15 PM (11 years ago)
Author:
shauno
Message:

Security patch to stop unauthorized access to certain features

Location:
nextgen-gallery-voting
Files:
34 added
2 edited

Legend:

Unmodified
Added
Removed
  • nextgen-gallery-voting/trunk/ngg-voting.php

    r893145 r1047338  
    44Plugin URI: http://shauno.co.za/wordpress/nextgen-gallery-voting/
    55Description: This plugin allows you to add user voting and rating to NextGEN Galleries and Images
    6 Version: 2.7.5
     6Version: 2.7.6
    77Author: Shaun Alberts
    88Author URI: http://shauno.co.za
     
    11861186                       
    11871187            $qry .= ' GROUP BY v.pid, v.criteria_id';
    1188             $qry .= ' ORDER BY avg '.$_GET['nggv']['order'].', num '.$_GET['nggv']['order'];
     1188            $qry .= ' ORDER BY avg '.$wpdb->escape($_GET['nggv']['order']).', num '.$wpdb->escape($_GET['nggv']['order']);
    11891189            if($_GET['nggv']['limit']) {
    1190                 $qry .= ' LIMIT 0, '.$_GET['nggv']['limit'];
     1190                $qry .= ' LIMIT 0, '.$wpdb->escape($_GET['nggv']['limit']);
    11911191            }
    11921192           
  • nextgen-gallery-voting/trunk/readme.txt

    r893145 r1047338  
    44Tags: nextgen-gallery, nextgen, gallery, voting, rating, ratings, nextgen-gallery-voting
    55Requires at least: 2.9.1
    6 Tested up to: 3.8.3
    7 Stable tag: 2.7.5
     6Tested up to: 4.0.1
     7Stable tag: 2.7.6
    88
    99Adds the ability for users to vote and rate your NextGEN Images. Simple options give you the ability to limit who can vote on what.
     
    7777
    7878== Changelog ==
     79
     80= 2.7.6 =
     81* Security patch to stop unauthorized access to certain features
    7982
    8083= 2.7.5 =
     
    230233== Upgrade Notice ==
    231234
     235= 2.7.6 =
     236Security patch to stop unauthorized access to certain features
     237
    232238= 2.7.5 =
    233239CSS fix for stopping numeric values of stars showing under certain conditions
Note: See TracChangeset for help on using the changeset viewer.