require($INC);
} elseif (!IS_MEMBER()) {
LOAD_URL("modules.php?module=index");
+} elseif ((!EXT_IS_ACTIVE("order")) && (!IS_ADMIN())) {
+ ADD_FATAL(EXTENSION_PROBLEM_EXT_INACTIVE, "order");
+ return;
} elseif ($BLOCK_MODE) {
// Block mode detected
return;
ADD_DESCR("member", __FILE__);
// Load the include file
-$INC_WHAT = sprintf("%sinc/modules/member/what-%s.php", PATH, $GLOBALS['what']);
+$INC_WHAT = sprintf("%sinc/modules/member/what-%s.php", PATH, SQL_ESCAPE($GLOBALS['what']));
if (FILE_READABLE($INC_WHAT)) {
// Ok, we finally load the member action module
include_once($INC_WHAT);