Changeset 4737

Show
Ignore:
Timestamp:
12/05/07 17:12:54 (12 months ago)
Author:
inureyes
Message:

#711

Location:
trunk
Files:
16 modified

Legend:

Unmodified
Added
Removed
  • trunk/components/Needlworks.Cache.PageCache.php

    r4735 r4737  
    135135        $result = DBQuery::queryCell("SELECT value FROM {$database['prefix']}PageCacheLog  
    136136            WHERE blogid = ".getBlogId()." 
    137             AND name = '".tc_escape_string($this->realName)."'"); 
     137            AND name = '".DBQuery::escapeString($this->realName)."'"); 
    138138        if($result !== null) { 
    139139            $this->_dbContents = unserialize($result); 
     
    151151        else $this->_dbContents['user'] = $this->dbContents; 
    152152        return DBQuery::execute("REPLACE INTO {$database['prefix']}PageCacheLog  
    153             VALUES(".getBlogId().", '".tc_escape_string($this->realName)."', '".tc_escape_string(serialize($this->_dbContents))."')"); 
     153            VALUES(".getBlogId().", '".DBQuery::escapeString($this->realName)."', '".tc_escape_string(serialize($this->_dbContents))."')"); 
    154154    } 
    155155 
     
    158158        return DBQuery::execute("DELETE FROM {$database['prefix']}PageCacheLog  
    159159            WHERE blogid = ".getBlogId()." 
    160             AND name = '".tc_escape_string($this->realName)."'");  
     160            AND name = '".DBQuery::escapeString($this->realName)."'");  
    161161    } 
    162162 
  • trunk/components/Needlworks.Database.php

    r4637 r4737  
    5151            $this->_attributes[$name] = 'NULL'; 
    5252        else 
    53             $this->_attributes[$name] = ($escape === null ? $value : ($escape ? '\'' . tc_escape_string($value) . '\'' : "'" . $value . "'")); 
     53            $this->_attributes[$name] = ($escape === null ? $value : ($escape ? '\'' . DBQuery::escapeString($value) . '\'' : "'" . $value . "'")); 
    5454    } 
    5555     
     
    7878            $this->_qualifiers[$name] = 'NULL'; 
    7979        else 
    80             $this->_qualifiers[$name] = ($escape === null ? $value : ($escape ? '\'' . tc_escape_string($value) . '\'' : "'" . $value . "'")); 
     80            $this->_qualifiers[$name] = ($escape === null ? $value : ($escape ? '\'' . DBQuery::escapeString($value) . '\'' : "'" . $value . "'")); 
    8181    } 
    8282     
  • trunk/components/Textcube.Control.Auth.php

    r4721 r4737  
    344344 
    345345        Acl::clearAcl(); 
    346         $loginid = tc_escape_string($loginid); 
     346        $loginid = DBQuery::escapeString($loginid); 
    347347 
    348348        $blogApiPassword = getBlogSetting("blogApiPassword", ""); 
     
    352352            $authtoken = DBQuery::queryCell("SELECT value FROM {$database['prefix']}UserSettings WHERE userid = '$userid' AND name = 'AuthToken' LIMIT 1"); 
    353353            if (!empty($authtoken)) { 
    354                 $password = tc_escape_string($password); 
     354                $password = DBQuery::escapeString($password); 
    355355                $secret = '(`password` = \'' . md5($password) . '\' OR \'' . $password . '\' = \'' . $authtoken . '\')'; 
    356356            } 
     
    359359            } 
    360360        } else if( $blogapi && !empty($blogApiPassword) ) { 
    361             $password = tc_escape_string($password); 
     361            $password = DBQuery::escapeString($password); 
    362362            $secret = '(`password` = \'' . md5($password) . '\' OR \'' . $password . '\' = \'' . $blogApiPassword . '\')'; 
    363363        } else { 
  • trunk/components/Textcube.Data.Category.php

    r4728 r4737  
    157157        if (empty($label)) 
    158158            return null; 
    159         return DBQuery::queryCell("SELECT id FROM {$database['prefix']}Categories WHERE blogid = ".getBlogId()." AND label = '" . tc_escape_string($label) . "'"); 
     159        return DBQuery::queryCell("SELECT id FROM {$database['prefix']}Categories WHERE blogid = ".getBlogId()." AND label = '" . DBQuery::escapeString($label) . "'"); 
    160160    } 
    161161     
  • trunk/components/Textcube.Data.Filter.php

    r4563 r4737  
    104104    function isFiltered($type, $value) { 
    105105        global $database; 
    106         $type = tc_escape_string($type); 
    107         $value = tc_escape_string($value); 
     106        $type = DBQuery::escapeString($type); 
     107        $value = DBQuery::escapeString($value); 
    108108        return DBQuery::queryExistence("SELECT * FROM {$database['prefix']}Filters WHERE blogid = ".getBlogId()." AND type = '$type' AND '$value' LIKE CONCAT('%', pattern, '%')"); 
    109109    } 
  • trunk/components/Textcube.Data.Link.php

    r4563 r4737  
    105105        if (empty($url)) 
    106106            return null; 
    107         return DBQuery::queryCell("SELECT id FROM {$database['prefix']}Links WHERE blogid = ".getBlogId()." AND url = '" . tc_escape_string($url) . "'"); 
     107        return DBQuery::queryCell("SELECT id FROM {$database['prefix']}Links WHERE blogid = ".getBlogId()." AND url = '" . DBQuery::escapeString($url) . "'"); 
    108108    } 
    109109     
  • trunk/components/Textcube.Data.PluginSetting.php

    r4563 r4737  
    8080        $query = new TableQuery($database['prefix'] . 'Plugins'); 
    8181        $query->setQualifier('blogid', getBlogId()); 
    82         $query->setQualifier('name', tc_escape_string(UTF8::lessenAsEncoding($this->name, 255)), true); 
     82        $query->setQualifier('name', DBQuery::escapeString(UTF8::lessenAsEncoding($this->name, 255)), true); 
    8383        if (isset($this->setting)) 
    84             $query->setAttribute('settings', tc_escape_string($this->setting), true); 
     84            $query->setAttribute('settings', DBQuery::escapeString($this->setting), true); 
    8585        return $query; 
    8686    } 
  • trunk/components/Textcube.Data.Post.php

    r4563 r4737  
    286286 
    287287        for ($i = 1; $i < 1000; $i++) { 
    288             $checkSlogan = tc_escape_string($this->slogan); 
     288            $checkSlogan = DBQuery::escapeString($this->slogan); 
    289289            $query->setAttribute('slogan', $checkSlogan, false); 
    290290            if (!DBQuery::queryExistence( 
     
    591591                $oldtag = DBQuery::queryRow("SELECT id, name FROM {$database['prefix']}Tags WHERE id = {$target['tag']}"); 
    592592                if ($oldtag != null) {       
    593                     $tagid = DBQuery::queryCell("SELECT id FROM {$database['prefix']}Tags WHERE name = '" . tc_escape_string($oldtag['name']) . "' LIMIT 1 "); 
     593                    $tagid = DBQuery::queryCell("SELECT id FROM {$database['prefix']}Tags WHERE name = '" . DBQuery::escapeString($oldtag['name']) . "' LIMIT 1 "); 
    594594                    if ($tagid == null) {  
    595595                        DBQuery::execute("DELETE FROM {$database['prefix']}TagRelations WHERE blogid = {$target['blogid']} AND tag = {$target['tag']} AND entry = {$target['entry']}"); 
  • trunk/components/Textcube.Data.Tag.php

    r4563 r4737  
    2525        $taglist = array(); 
    2626        foreach($tmptaglist as $tag) { 
    27             $tag = tc_escape_string(UTF8::lessenAsEncoding(trim($tag), 255)); 
     27            $tag = DBQuery::escapeString(UTF8::lessenAsEncoding(trim($tag), 255)); 
    2828            array_push($taglist, $tag); 
    2929        } 
     
    7171        $taglist = array(); 
    7272        foreach($tmptaglist as $tag) { 
    73             $tag = tc_escape_string(trim($tag)); 
     73            $tag = DBQuery::escapeString(trim($tag)); 
    7474            array_push($taglist, $tag); 
    7575        } 
     
    8686        $oldtaglist = array(); 
    8787        foreach($tmpoldtaglist as $tag) { 
    88             $tag = tc_escape_string(UTF8::lessenAsEncoding(trim($tag), 255)); 
     88            $tag = DBQuery::escapeString(UTF8::lessenAsEncoding(trim($tag), 255)); 
    8989            array_push($oldtaglist, $tag); 
    9090        } 
  • trunk/components/Textcube.Function.misc.php

    r4638 r4737  
    277277        } 
    278278         
    279         $escape_name = tc_escape_string($name); 
    280         $escape_value = tc_escape_string($value); 
     279        $escape_name = DBQuery::escapeString($name); 
     280        $escape_value = DBQuery::escapeString($value); 
    281281         
    282282        if (array_key_exists($name, $__gCacheBlogSettings[$blogid])) { 
     
    306306        } 
    307307         
    308         $escape_name = tc_escape_string($name); 
     308        $escape_name = DBQuery::escapeString($name); 
    309309         
    310310        if (array_key_exists($name, $__gCacheBlogSettings[$blogid])) { 
     
    346346        global $database; 
    347347        $name = 'plugin_' . $name; 
    348         $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".tc_escape_string($name)."'"); 
     348        $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".DBQuery::escapeString($name)."'"); 
    349349        return ($value === null) ? $default : $value; 
    350350    } 
     
    352352    function getUserSettingGlobal($name, $default = null) { 
    353353        global $database; 
    354         $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".tc_escape_string($name)."'"); 
     354        $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".DBQuery::escapeString($name)."'"); 
    355355        return ($value === null) ? $default : $value; 
    356356    } 
     
    359359        global $database; 
    360360        $name = 'plugin_' . $name; 
    361         $name = tc_escape_string($name); 
    362         $value = tc_escape_string($value); 
     361        $name = DBQuery::escapeString($name); 
     362        $value = DBQuery::escapeString($value); 
    363363        return DBQuery::execute("REPLACE INTO {$database['prefix']}UserSettings VALUES(".getUserId().", '$name', '$value')"); 
    364364    } 
     
    367367        global $database; 
    368368        $name = 'plugin_' . $name; 
    369         return DBQuery::execute("DELETE FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".tc_escape_string($name)."'"); 
     369        return DBQuery::execute("DELETE FROM {$database['prefix']}UserSettings WHERE userid = ".getUserId()." AND name = '".DBQuery::escapeString($name)."'"); 
    370370    } 
    371371 
     
    373373        global $database; 
    374374        $name = 'plugin_' . $name; 
    375         $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}ServiceSettings WHERE name = '".tc_escape_string($name)."'"); 
     375        $value = DBQuery::queryCell("SELECT value FROM {$database['prefix']}ServiceSettings WHERE name = '".DBQuery::escapeString($name)."'"); 
    376376        return ($value === null) ? $default : $value; 
    377377    } 
     
    380380        global $database; 
    381381        $name = 'plugin_' . $name; 
    382         $name = tc_escape_string(UTF8::lessenAsEncoding($name, 32)); 
    383         $value = tc_escape_string(UTF8::lessenAsEncoding($value, 255)); 
     382        $name = DBQuery::escapeString(UTF8::lessenAsEncoding($name, 32)); 
     383        $value = DBQuery::escapeString(UTF8::lessenAsEncoding($value, 255)); 
    384384        return DBQuery::execute("REPLACE INTO {$database['prefix']}ServiceSettings VALUES('$name', '$value')"); 
    385385    } 
     
    388388        global $database; 
    389389        $name = 'plugin_' . $name; 
    390         return DBQuery::execute("DELETE FROM {$database['prefix']}ServiceSettings WHERE name = '".tc_escape_string($name)."'"); 
     390        return DBQuery::execute("DELETE FROM {$database['prefix']}ServiceSettings WHERE name = '".DBQuery::escapeString($name)."'"); 
    391391    } 
    392392     
     
    399399    function setBlogSettingRowsPerPage($value) { 
    400400        global $database, $blogid; 
    401         $value = tc_escape_string($value); 
     401        $value = DBQuery::escapeString($value); 
    402402        return DBQuery::execute("REPLACE INTO {$database['prefix']}BlogSettings VALUES($blogid, 'rowsPerPage', '$value')"); 
    403403    } 
  • trunk/components/Textcube.Model.Statistics.php

    r4563 r4737  
    9191                    if (!fireEvent('AddingRefererLog', true, array('host' => $referer['host'], 'url' => $_SERVER['HTTP_REFERER']))) 
    9292                        return; 
    93                     $host = tc_escape_string(UTF8::lessenAsEncoding($referer['host'], 64)); 
    94                     $url = tc_escape_string(UTF8::lessenAsEncoding($_SERVER['HTTP_REFERER'], 255)); 
     93                    $host = DBQuery::escapeString(UTF8::lessenAsEncoding($referer['host'], 64)); 
     94                    $url = DBQuery::escapeString(UTF8::lessenAsEncoding($_SERVER['HTTP_REFERER'], 255)); 
    9595                    mysql_query("insert into {$database['prefix']}RefererLogs values($blogid, '$host', '$url', UNIX_TIMESTAMP())"); 
    9696                    mysql_query("delete from {$database['prefix']}RefererLogs where referred < UNIX_TIMESTAMP() - 604800"); 
  • trunk/plugins/CL_OpenID/index.php

    r4712 r4737  
    166166    global $database, $blogid; 
    167167    global $openid_session; 
    168     $openid = tc_escape_string($openid); 
    169     $delegatedid = tc_escape_string($delegatedid); 
     168    $openid = DBQuery::escapeString($openid); 
     169    $delegatedid = DBQuery::escapeString($delegatedid); 
    170170 
    171171    $query = "SELECT data FROM {$database['prefix']}OpenIDUsers WHERE openid='{$openid}'"; 
     
    205205{ 
    206206    global $database, $blogid; 
    207     $openid = tc_escape_string($openid); 
     207    $openid = DBQuery::escapeString($openid); 
    208208 
    209209    $query = "SELECT openid FROM {$database['prefix']}OpenIDUsers WHERE blogid={$blogid} and openid='{$openid}'"; 
  • trunk/plugins/CL_OpenID/openid_session.php

    r4563 r4737  
    8989 
    9090    $data = serialize( $openid_session ); 
    91     $server = tc_escape_string($_SERVER['HTTP_HOST']); 
    92     $request = tc_escape_string($_SERVER['REQUEST_URI']); 
    93     $referer = isset($_SERVER['HTTP_REFERER']) ? tc_escape_string($_SERVER['HTTP_REFERER']) : ''; 
     91    $server = DBQuery::escapeString($_SERVER['HTTP_HOST']); 
     92    $request = DBQuery::escapeString($_SERVER['REQUEST_URI']); 
     93    $referer = isset($_SERVER['HTTP_REFERER']) ? DBQuery::escapeString($_SERVER['HTTP_REFERER']) : ''; 
    9494    $timer = getMicrotimeAsFloat() - $sessionMicrotime; 
    9595    $result = DBQuery::query("UPDATE {$database['prefix']}Sessions SET data = '$data', server = '$server', request = '$request', referer = '$referer', timer = $timer, updated = UNIX_TIMESTAMP() WHERE id = '$openid_session_id' AND address = '" . _openid_ip_address() . "'"); 
  • trunk/plugins/EAS/index.php

    r4563 r4737  
    2222        { 
    2323            $sql = 'SELECT COUNT(id) as cc FROM ' . $database['prefix'] . 'Trackbacks WHERE'; 
    24             $sql .= ' url = \'' . tc_escape_string($url) . '\''; 
     24            $sql .= ' url = \'' . DBQuery::escapeString($url) . '\''; 
    2525            $sql .= ' AND isFiltered > 0'; 
    2626             
     
    3434 
    3535            $sql = 'SELECT COUNT(id) as cc FROM ' . $database['prefix'] . 'Comments WHERE'; 
    36             $sql .= ' comment = \'' . tc_escape_string($content) . '\''; 
    37             $sql .= ' AND homepage = \'' . tc_escape_string($url) . '\''; 
    38             $sql .= ' AND name = \'' . tc_escape_string($name) . '\''; 
     36            $sql .= ' comment = \'' . DBQuery::escapeString($content) . '\''; 
     37            $sql .= ' AND homepage = \'' . DBQuery::escapeString($url) . '\''; 
     38            $sql .= ' AND name = \'' . DBQuery::escapeString($name) . '\''; 
    3939            $sql .= ' AND isFiltered > 0'; 
    4040             
     
    4747        // Check IP 
    4848        $sql = 'SELECT COUNT(id) as cc FROM ' . $tableName . ' WHERE'; 
    49         $sql .= ' ip = \'' . tc_escape_string($_SERVER['REMOTE_ADDR']) . '\''; 
     49        $sql .= ' ip = \'' . DBQuery::escapeString($_SERVER['REMOTE_ADDR']) . '\''; 
    5050        $sql .= ' AND isFiltered > 0'; 
    5151 
  • trunk/plugins/PN_Subscription_Default/index.php

    r4714 r4737  
    304304    if (Filter::isFiltered('ip', $_SERVER['REMOTE_ADDR'])) 
    305305        return; 
    306     $ip = tc_escape_string($_SERVER['REMOTE_ADDR']); 
    307     $host = tc_escape_string(isset($_SERVER['REMOTE_HOST']) ? $_SERVER['REMOTE_HOST'] : ''); 
    308     $useragent = tc_escape_string(isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : ''); 
     306    $ip = DBQuery::escapeString($_SERVER['REMOTE_ADDR']); 
     307    $host = DBQuery::escapeString(isset($_SERVER['REMOTE_HOST']) ? $_SERVER['REMOTE_HOST'] : ''); 
     308    $useragent = DBQuery::escapeString(isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : ''); 
    309309    mysql_query("insert into {$database['prefix']}SubscriptionLogs values($blogid, '$ip', '$host', '$useragent', UNIX_TIMESTAMP())"); 
    310310    mysql_query("delete from {$database['prefix']}SubscriptionLogs where referred < UNIX_TIMESTAMP() - 604800"); 
  • trunk/plugins/ST_TeamBlogSettings/index.php

    r4571 r4737  
    265265            } 
    266266        }else if($flag == "profile"){ 
    267             $profile = tc_escape_string(UTF8::lessenAsEncoding($profile, 65535)); 
     267            $profile = DBQuery::escapeString(UTF8::lessenAsEncoding($profile, 65535)); 
    268268            if(DBQuery::execute("UPDATE {$database['prefix']}TeamUserSettings SET profile=\"{$profile}\", updated=UNIX_TIMESTAMP() WHERE blogid=".getBlogId()." and userid=".getUserId())){ 
    269269                respondResultPage(0);