]> git.mxchange.org Git - mailer.git/blobdiff - inc/modules/admin/what-admin_add.php
Unnessarry addslashes() and SQL_ESCAPE() removed, some added, some bigintval() added
[mailer.git] / inc / modules / admin / what-admin_add.php
index fa44c2de380af8a0ece0ccf0876240d565493d43..483a4b15e82478a9d189b0e970afcc0cafa31845 100644 (file)
@@ -38,7 +38,7 @@ if ((!defined('__SECURITY')) || (!IS_ADMIN())) {
 }
 
 // Add description as navigation point
-ADD_DESCR("admin", basename(__FILE__));
+ADD_DESCR("admin", __FILE__);
 
 // Check if the admin has entered title and what-php file name...
 if (((empty($_POST['title'])) || (empty($_POST['menu'])) || (empty($_POST['descr']))) && (isset($_POST['ok']))) {
@@ -170,28 +170,28 @@ if (!isset($_POST['ok']))
        if (!empty($_POST['menu']))
        {
                // Add sub menu
-               $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_admin_menu (`action`,`what`,`title`,`descr`,`sort`)
-VALUES('%s','%s','%s','%s','%s')",
- array(
-       $_POST['menu'],
-       $_POST['name'],
-       $_POST['title'],
-       addslashes($_POST['descr']),
-       bigintval($_POST['sort']),
-), __FILE__, __LINE__);
+               $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_admin_menu (`action`,`what`,`title`,`descr`,`sort`) VALUES ('%s','%s','%s','%s','%s')",
+                       array(
+                               $_POST['menu'],
+                               $_POST['name'],
+                               $_POST['title'],
+                               $_POST['descr'],
+                               bigintval($_POST['sort']),
+                       ), __FILE__, __LINE__
+               );
                CACHE_PURGE_ADMIN_MENU(0, $_POST['menu'], $_POST['name']);
        }
         else
        {
                // Add main menu
-               $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, title, descr, sort)
-VALUES('%s','%s','%s','%s')",
- array(
-       $_POST['name'],
-       $_POST['title'],
-       addslashes($_POST['descr']),
-       bigintval($_POST['sort']),
-), __FILE__, __LINE__);
+               $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, title, descr, sort) VALUES ('%s','%s','%s','%s')",
+                       array(
+                               $_POST['name'],
+                               $_POST['title'],
+                               $_POST['descr'],
+                               bigintval($_POST['sort']),
+                       ), __FILE__, __LINE__
+               );
                CACHE_PURGE_ADMIN_MENU(0, $_POST['name']);
        }
        LOAD_TEMPLATE("admin_settings_saved", false, SAVING_DONE);