All database names are now 'back-ticked' and constant _MYSQL_PREFIX is wrapped. Partl...
[mailer.git] / inc / libs / sponsor_functions.php
index 6e07f8f46c89513a469ccac4cd7a46da3e29617f..50b0d509cb9896b501c14b6f45798c40ec0a7525 100644 (file)
@@ -69,7 +69,7 @@ function SPONSOR_HANDLE_SPONSOR (&$POST, $NO_UPDATE=false, $MSGs=array(), $RET_S
                                        $SAVE = false;
                                } else {
                                        // Do we want to add a new sponsor or update his data?
-                                       $result = SQL_QUERY_ESC("SELECT id FROM `"._MYSQL_PREFIX."_sponsor_data` WHERE email='%s' LIMIT 1",
+                                       $result = SQL_QUERY_ESC("SELECT id FROM `{!MYSQL_PREFIX!}_sponsor_data` WHERE email='%s' LIMIT 1",
                                                array($POST['email']), __FILE__, __LINE__);
 
                                        // Is a sponsor alread in the db?
@@ -125,7 +125,7 @@ function SPONSOR_HANDLE_SPONSOR (&$POST, $NO_UPDATE=false, $MSGs=array(), $RET_S
                // Update?
                if ($UPDATE) {
                        // Update his data
-                       $SQL = "UPDATE `"._MYSQL_PREFIX."_sponsor_data` SET ";
+                       $SQL = "UPDATE `{!MYSQL_PREFIX!}_sponsor_data` SET ";
                        foreach ($DATA['keys'] as $k => $v) {
                                $SQL .= $v."='%s', ";
                        }
@@ -160,7 +160,7 @@ function SPONSOR_HANDLE_SPONSOR (&$POST, $NO_UPDATE=false, $MSGs=array(), $RET_S
                        $VALUES = str_repeat("%s', '", count($DATA['values']) - 1);
 
                        // Generate string
-                       $SQL = "INSERT INTO `"._MYSQL_PREFIX."_sponsor_data` (".$KEYS.") VALUES ('".$VALUES."%s')";
+                       $SQL = "INSERT INTO `{!MYSQL_PREFIX!}_sponsor_data` (".$KEYS.") VALUES ('".$VALUES."%s')";
 
                        // Generate message
                        $MSG = SPONSOR_GET_MESSAGE(ADMIN_SPONSOR_ADDED, "added", $MSGs);
@@ -264,7 +264,7 @@ function IS_SPONSOR () {
        $ret = false;
        if ((isSessionVariableSet('sponsorid'))) && (isSessionVariableSet('sponsorpass')))) {
                // Check cookies against database records...
-               $result = SQL_QUERY_ESC("SELECT id FROM `"._MYSQL_PREFIX."_sponsor_data`
+               $result = SQL_QUERY_ESC("SELECT id FROM `{!MYSQL_PREFIX!}_sponsor_data`
 WHERE id='%s' AND password='%s' AND status='CONFIRMED' LIMIT 1",
                        array(bigintval(get_session('sponsorid')), get_session('sponsorpass')), __FILE__, __LINE__);
                if (SQL_NUMROWS($result) == 1) {
@@ -287,7 +287,7 @@ function GENERATE_SPONSOR_MENU($current)
        if (IS_ADMIN()) $WHERE = "";
 
        // Load main menu entries
-       $result_main = SQL_QUERY("SELECT action, title FROM `"._MYSQL_PREFIX."_sponsor_menu`
+       $result_main = SQL_QUERY("SELECT action, title FROM `{!MYSQL_PREFIX!}_sponsor_menu`
 WHERE (what='' OR what IS NULL) ".$WHERE."
 ORDER BY sort", __FILE__, __LINE__);
        if (SQL_NUMROWS($result_main) > 0)
@@ -296,7 +296,7 @@ ORDER BY sort", __FILE__, __LINE__);
                while(list($action, $title_main) = SQL_FETCHROW($result_main))
                {
                        // Load sub menus
-                       $result_sub = SQL_QUERY_ESC("SELECT what, title FROM `"._MYSQL_PREFIX."_sponsor_menu`
+                       $result_sub = SQL_QUERY_ESC("SELECT what, title FROM `{!MYSQL_PREFIX!}_sponsor_menu`
 WHERE action='%s' AND what != '' AND what IS NOT NULL ".$WHERE."
 ORDER BY sort", array($action), __FILE__, __LINE__);
                        if (SQL_NUMROWS($result_sub) > 0)
@@ -374,7 +374,7 @@ function UPDATE_SPONSOR_LOGIN () {
        // Is sponsor?
        if (IS_SPONSOR()) {
                // Update last online timestamp
-               SQL_QUERY_ESC("UPDATE `"._MYSQL_PREFIX."_sponsor_data`
+               SQL_QUERY_ESC("UPDATE `{!MYSQL_PREFIX!}_sponsor_data`
 SET last_online=UNIX_TIMESTAMP()
 WHERE id='%s' AND password='%s' LIMIT 1",
                        array(bigintval(get_session('sponsorid')), get_session('sponsorpass')), __FILE__, __LINE__);
@@ -417,7 +417,7 @@ function SPONSOR_SAVE_DATA ($POST, $content) {
        $DATA = array();
 
        // Prepare SQL string
-       $SQL = "UPDATE `"._MYSQL_PREFIX."_sponsor_data` SET";
+       $SQL = "UPDATE `{!MYSQL_PREFIX!}_sponsor_data` SET";
        foreach ($POST as $key => $value) {
                // Mmmmm, too less security here???
                $SQL   .= " ".strip_tags($key)."='%s',";