Changeset 1467925
- Timestamp:
- 08/04/2016 04:12:37 PM (9 years ago)
- Location:
- formbuilder/trunk
- Files:
-
- 6 edited
-
class/FBFormEditor.class.php (modified) (3 diffs)
-
html/options_edit_form.inc.php (modified) (2 diffs)
-
php/formbuilder_admin_pages.inc.php (modified) (13 diffs)
-
php/formbuilder_parser.php (modified) (1 diff)
-
php/formbuilder_post_metabox.inc.php (modified) (3 diffs)
-
php/formbuilder_processing.inc.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
formbuilder/trunk/class/FBFormEditor.class.php
r371672 r1467925 116 116 # $tableFields->remove_row($fieldKey); 117 117 118 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";118 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 119 119 $results = $wpdb->get_results($sql, ARRAY_A); 120 120 $actionRow = $results[0]; 121 121 122 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order ASC;";122 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order ASC;"; 123 123 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 124 124 … … 145 145 # $relatedRows = $tableFields->search_rows("$form_id", "form_id", "display_order ASC"); 146 146 147 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";147 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 148 148 $results = $wpdb->get_results($sql, ARRAY_A); 149 149 $actionRow = $results[0]; 150 150 151 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order ASC;";151 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order ASC;"; 152 152 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 153 153 … … 186 186 { 187 187 # $actionRow = $tableFields->load_row($fieldKey); 188 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";188 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 189 189 $results = $wpdb->get_results($sql, ARRAY_A); 190 190 $actionRow = $results[0]; 191 191 192 192 # $relatedRows = $tableFields->search_rows("$form_id", "form_id", "display_order DESC"); 193 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order DESC;";193 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order DESC;"; 194 194 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 195 195 -
formbuilder/trunk/html/options_edit_form.inc.php
r1030489 r1467925 230 230 // Tag display and customization. 231 231 $tags = array(); 232 $form_id = is_numeric($form_id) ? $form_id : 0; 232 233 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_TAGS . " WHERE form_id = '{$form_id}' ORDER BY tag ASC;"; 233 234 $results = $wpdb->get_results($sql, ARRAY_A); … … 270 271 271 272 <?php 273 $form_id = is_numeric($form_id) ? $form_id : 0; 272 274 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_id ORDER BY display_order ASC;"; 273 275 $related = $wpdb->get_results($sql, ARRAY_A); -
formbuilder/trunk/php/formbuilder_admin_pages.inc.php
r1030489 r1467925 178 178 { 179 179 global $wpdb; 180 if(!is_numeric($form_id)) 181 return; 180 182 181 183 /* … … 294 296 { 295 297 $fieldAction = $_POST['fieldAction']; 296 $fieldKey = key($fieldAction);298 $fieldKey = addslashes(htmlentities(key($fieldAction))); 297 299 $fieldValue = current($fieldAction); 298 300 … … 301 303 if($fieldKey == "newField") 302 304 { // Create a new field at the end of the form. 303 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order DESC;";305 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order DESC;"; 304 306 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 305 307 # $relatedRows = $tableFields->search_rows("$form_id", "form_id", "display_order DESC"); … … 322 324 if($fieldValue == __("Add Another", 'formbuilder')) 323 325 { 324 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";326 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 325 327 $results = $wpdb->get_results($sql, ARRAY_A); 326 328 $actionRow = $results[0]; … … 328 330 329 331 330 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order DESC;";332 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order DESC;"; 331 333 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 332 334 #$relatedRows = $tableFields->search_rows("$form_id", "form_id"); … … 364 366 # $tableFields->remove_row($fieldKey); 365 367 366 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";368 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 367 369 $results = $wpdb->get_results($sql, ARRAY_A); 368 370 $actionRow = $results[0]; 369 371 370 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order ASC;";372 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order ASC;"; 371 373 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 372 374 … … 393 395 # $relatedRows = $tableFields->search_rows("$form_id", "form_id", "display_order ASC"); 394 396 395 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";397 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 396 398 $results = $wpdb->get_results($sql, ARRAY_A); 397 399 $actionRow = $results[0]; 398 400 399 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order ASC;";401 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order ASC;"; 400 402 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 401 403 … … 434 436 { 435 437 # $actionRow = $tableFields->load_row($fieldKey); 436 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = $fieldKeyORDER BY display_order DESC;";438 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '$fieldKey' ORDER BY display_order DESC;"; 437 439 $results = $wpdb->get_results($sql, ARRAY_A); 438 440 $actionRow = $results[0]; 439 441 440 442 # $relatedRows = $tableFields->search_rows("$form_id", "form_id", "display_order DESC"); 441 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order DESC;";443 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order DESC;"; 442 444 $relatedRows = $wpdb->get_results($sql, ARRAY_A); 443 445 … … 629 631 { 630 632 global $wpdb; 633 if(!is_numeric($form_id)) 634 return; 631 635 632 636 if(!formbuilder_user_can('create')) … … 643 647 $form = $results[0]; 644 648 645 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = $form_idORDER BY display_order ASC;";649 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE form_id = '$form_id' ORDER BY display_order ASC;"; 646 650 $fields = $wpdb->get_results($sql, ARRAY_A); 647 651 if($fields) … … 659 663 $form['autoresponse'] = $autoresponse; 660 664 661 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_TAGS . " WHERE form_id = $form_id;";665 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_TAGS . " WHERE form_id = '$form_id';"; 662 666 $tags = $wpdb->get_results($sql, ARRAY_A); 663 667 if($tags) … … 896 900 { 897 901 global $wpdb; 902 if(!is_numeric($form_id)) 903 return; 898 904 899 905 if(!formbuilder_user_can('create')) … … 944 950 { 945 951 global $wpdb; 952 if(!is_numeric($form_id)) 953 return; 946 954 947 955 if(!formbuilder_user_can('create')) -
formbuilder/trunk/php/formbuilder_parser.php
r1460325 r1467925 36 36 37 37 session_start(); 38 if(!is_numeric($field_id)) 39 die(); 38 40 39 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = ' " . $_GET['fieldid'] . "';";41 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_FIELDS . " WHERE id = '{$field_id}';"; 40 42 $results = $wpdb->get_results($sql, ARRAY_A); 41 43 $field = $results[0]; -
formbuilder/trunk/php/formbuilder_post_metabox.inc.php
r906598 r1467925 85 85 86 86 // If the post already has an id, determine whether or not there is a form already linked to it. 87 if( $post->ID)87 if(is_numeric($post->ID)) 88 88 { 89 89 // Determine if the post/page has a linked form. … … 136 136 $id = $_REQUEST[ 'post_ID' ]; 137 137 138 if(!is_numeric($id)) 139 return; 140 138 141 // Get any fb entries for the given page ID. 139 142 $sql = "SELECT * FROM " . FORMBUILDER_TABLE_PAGES . " WHERE post_id = '" . $id . "';"; … … 185 188 if( !isset( $id ) ) 186 189 $id = $_REQUEST[ 'post_ID' ]; 190 if(!is_numeric($id)) 191 return; 187 192 188 193 $sql = "DELETE FROM " . FORMBUILDER_TABLE_PAGES . " WHERE post_id = '$id';"; -
formbuilder/trunk/php/formbuilder_processing.inc.php
r1030943 r1467925 126 126 define('SID', ''); 127 127 } 128 129 if(!is_numeric($form_id)) 130 return; 128 131 129 132 $formBuilderTextStrings = formbuilder_load_strings();
Note: See TracChangeset
for help on using the changeset viewer.