Quick Search:

Mode

Context

Displaying 3 lines of context. None | Less | More | Full

Other Diffs

Ignore

Blank Lines Whitespace:

Diff

477
 
1755
 
1755
 
languages.php
_> 11 <?php
  22 /*
<> 3 -  $Id: languages.php,v 1.35 2003/06/29 22:50:52 hpdl Exp $
   3+  $Id: languages.php 1755 2007-12-21 14:02:36Z hpdl $
44 
  55   osCommerce, Open Source E-Commerce Solutions
  66   http://www.oscommerce.com
  77 
<> 8 -  Copyright (c) 2003 osCommerce
   8+  Copyright (c) 2007 osCommerce
99 
  1010   Released under the GNU General Public License
  1111 */
     
 !
1818     switch ($action) {
  1919       case 'insert':
  2020         $name = tep_db_prepare_input($HTTP_POST_VARS['name']);
<> 21 -        $code = tep_db_prepare_input($HTTP_POST_VARS['code']);
   21+        $code = tep_db_prepare_input(substr($HTTP_POST_VARS['code'], 0, 2));
2222         $image = tep_db_prepare_input($HTTP_POST_VARS['image']);
  2323         $directory = tep_db_prepare_input($HTTP_POST_VARS['directory']);
<> 24 -        $sort_order = tep_db_prepare_input($HTTP_POST_VARS['sort_order']);
   24+        $sort_order = (int)tep_db_prepare_input($HTTP_POST_VARS['sort_order']);
2525 
  2626         tep_db_query("insert into " . TABLE_LANGUAGES . " (name, code, image, directory, sort_order) values ('" . tep_db_input($name) . "', '" . tep_db_input($code) . "', '" . tep_db_input($image) . "', '" . tep_db_input($directory) . "', '" . tep_db_input($sort_order) . "')");
  2727         $insert_id = tep_db_insert_id();
     
 !
7171       case 'save':
  7272         $lID = tep_db_prepare_input($HTTP_GET_VARS['lID']);
  7373         $name = tep_db_prepare_input($HTTP_POST_VARS['name']);
<> 74 -        $code = tep_db_prepare_input($HTTP_POST_VARS['code']);
   74+        $code = tep_db_prepare_input(substr($HTTP_POST_VARS['code'], 0, 2));
7575         $image = tep_db_prepare_input($HTTP_POST_VARS['image']);
  7676         $directory = tep_db_prepare_input($HTTP_POST_VARS['directory']);
<> 77 -        $sort_order = tep_db_prepare_input($HTTP_POST_VARS['sort_order']);
   77+        $sort_order = (int)tep_db_prepare_input($HTTP_POST_VARS['sort_order']);
<_ 7878 
  7979         tep_db_query("update " . TABLE_LANGUAGES . " set name = '" . tep_db_input($name) . "', code = '" . tep_db_input($code) . "', image = '" . tep_db_input($image) . "', directory = '" . tep_db_input($directory) . "', sort_order = '" . tep_db_input($sort_order) . "' where languages_id = '" . (int)$lID . "'");
  8080