  |
1 | 1 | | <?php |
| |
2 | 2 | | /* |
  |
3 | | - | $Id: categories.php 1754 2007-12-21 13:15:40Z hpdl $ |
| |
| 3 | + | $Id: categories.php 1755 2007-12-21 14:02:36Z hpdl $ |
|
4 | 4 | | |
| |
5 | 5 | | osCommerce, Open Source E-Commerce Solutions |
| |
6 | 6 | | http://www.oscommerce.com |
| |
|
|
 |
… |
|
38 | 38 | | if (isset($HTTP_POST_VARS['categories_id'])) $categories_id = tep_db_prepare_input($HTTP_POST_VARS['categories_id']); |
| |
39 | 39 | | $sort_order = tep_db_prepare_input($HTTP_POST_VARS['sort_order']); |
| |
40 | 40 | | |
  |
41 | | - | $sql_data_array = array('sort_order' => $sort_order); |
| |
| 41 | + | $sql_data_array = array('sort_order' => (int)$sort_order); |
|
42 | 42 | | |
| |
43 | 43 | | if ($action == 'insert_category') { |
| |
44 | 44 | | $insert_sql_data = array('parent_id' => $current_category_id, |
| |
|
|
 |
… |
|
215 | 215 | | |
| |
216 | 216 | | $products_date_available = (date('Y-m-d') < $products_date_available) ? $products_date_available : 'null'; |
| |
217 | 217 | | |
  |
218 | | - | $sql_data_array = array('products_quantity' => tep_db_prepare_input($HTTP_POST_VARS['products_quantity']), |
| |
| 218 | + | $sql_data_array = array('products_quantity' => (int)tep_db_prepare_input($HTTP_POST_VARS['products_quantity']), |
|
219 | 219 | | 'products_model' => tep_db_prepare_input($HTTP_POST_VARS['products_model']), |
| |
220 | 220 | | 'products_price' => tep_db_prepare_input($HTTP_POST_VARS['products_price']), |
| |
221 | 221 | | 'products_date_available' => $products_date_available, |
  |
222 | | - | 'products_weight' => tep_db_prepare_input($HTTP_POST_VARS['products_weight']), |
| |
| 222 | + | 'products_weight' => (float)tep_db_prepare_input($HTTP_POST_VARS['products_weight']), |
|
223 | 223 | | 'products_status' => tep_db_prepare_input($HTTP_POST_VARS['products_status']), |
| |
224 | 224 | | 'products_tax_class_id' => tep_db_prepare_input($HTTP_POST_VARS['products_tax_class_id']), |
  |
225 | | - | 'manufacturers_id' => tep_db_prepare_input($HTTP_POST_VARS['manufacturers_id'])); |
| |
| 225 | + | 'manufacturers_id' => (int)tep_db_prepare_input($HTTP_POST_VARS['manufacturers_id'])); |
  |
226 | 226 | | |
| |
227 | 227 | | if (isset($HTTP_POST_VARS['products_image']) && tep_not_null($HTTP_POST_VARS['products_image']) && ($HTTP_POST_VARS['products_image'] != 'none')) { |
| |
228 | 228 | | $sql_data_array['products_image'] = tep_db_prepare_input($HTTP_POST_VARS['products_image']); |