X-Git-Url: https://git.mxchange.org/?p=mailer.git;a=blobdiff_plain;f=inc%2Fmodules%2Fframetester.php;h=49b06b359e17ef12edd66f6b8d131012cad1f3bb;hp=2f44befb0afbd27e669900c21d15bf8c16215587;hb=d997f1621c6e6e0427166bd96690e0825387dadd;hpb=19cd0d37b2bcbf9dd4f3c38a9cecd7f5011d6b66 diff --git a/inc/modules/frametester.php b/inc/modules/frametester.php index 2f44befb0a..49b06b359e 100644 --- a/inc/modules/frametester.php +++ b/inc/modules/frametester.php @@ -43,7 +43,7 @@ if (!empty($_GET['order'])) { // Order number placed, is he also logged in? if(IS_LOGGED_IN()) { // Ok, test passed... :) - $result = SQL_QUERY_ESC("SELECT subject, url FROM "._MYSQL_PREFIX."_pool WHERE id=%d AND sender=%d AND data_type='TEMP' LIMIT 1", + $result = SQL_QUERY_ESC("SELECT subject, url FROM "._MYSQL_PREFIX."_pool WHERE id=%s AND sender=%s AND data_type='TEMP' LIMIT 1", array(bigintval($_GET['order']), $GLOBALS['userid']), __FILE__, __LINE__); // Finally is the entry valid? @@ -71,11 +71,14 @@ if (!empty($_GET['order'])) { } if ((!empty($_POST['url'])) || (!empty($_GET['url'])) || (!empty($_GET['frame']))) { + // Default URL is ours $url = URL; - if (!empty($_POST['url'])) $url = $_POST['url']; - // Decode URL if set - if (!empty($_GET['url'])) $url = base64_decode(urldecode(COMPILE_CODE($_GET['url']))); + // Decode URL if set in GET parameters + if (!empty($_GET['url'])) $url = COMPILE_CODE(gzuncompress(base64_decode(urldecode($_GET['url'])))); + + // Use URL from POST data if set + if (!empty($_POST['url'])) $url = $_POST['url']; // Add missing element $frame = "";