if (isset($_POST['ok']))
{
// Make mail editable...
- $result = SQL_QUERY_ESC("SELECT subject, text, url FROM "._MYSQL_PREFIX."_pool WHERE id=%d LIMIT 1",
+ $result = SQL_QUERY_ESC("SELECT subject, text, url FROM "._MYSQL_PREFIX."_pool WHERE id=%s LIMIT 1",
array(bigintval($_POST['id'])), __FILE__, __LINE__);
list($subj, $text, $url) = SQL_FETCHROW($result);
SQL_FREERESULT($result);
define('__ID_VALUE' , $_POST['id']);
- define('__URL_VALUE' , stripslashes($url));
- define('__SUBJ_VALUE', stripslashes($subj));
- define('__TEXT_VALUE', stripslashes($text));
+ define('__URL_VALUE' , $url);
+ define('__SUBJ_VALUE', $subj);
+ define('__TEXT_VALUE', $text);
// Load template
LOAD_TEMPLATE("admin_edit_email");
subject='%s',
text='%s',
url='%s'
-WHERE id=%d LIMIT 1",
+WHERE id=%s LIMIT 1",
array(
addslashes($_POST['subj']),
addslashes($_POST['text']),
else
{
// No mail orders left in pool
- OUTPUT_HTML ("<SPAN class=\"admin_failed\">".ADMIN_NO_MAILS_IN_POOL."</SPAN>");
+ OUTPUT_HTML("<SPAN class=\"admin_failed\">".ADMIN_NO_MAILS_IN_POOL."</SPAN>");
}
CLOSE_TABLE();
//