Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions csfmanager/csfmanager.php
Original file line number Diff line number Diff line change
Expand Up @@ -331,7 +331,7 @@ function csfmanager_clientarea($vars)
{
$sql = "SELECT *
FROM mod_csfmanager_allow_keys
WHERE key_hash = '" . mysql_escape_string($key) . "'
WHERE key_hash = '" . mysqli_real_escape_string($key) . "'
AND key_clicks_remained > 0
AND key_expire > '" . time() . "'
AND key_cancelled = 0";
Expand Down Expand Up @@ -399,7 +399,7 @@ function csfmanager_clientarea($vars)
$now = time();

$sql = "INSERT INTO mod_csfmanager_allow (`clientid`,`serverid`,`ip`,`time`,`expiration`,`reason`) VALUES
('{$key_details['user_id']}','{$product_details['server_id']}','{$ip}','{$now}','" . ($now + ($allowlength[strtolower($instance->getConfig('allowlength_type'))] * $instance->getConfig('allowlength'))) . "','" . mysql_escape_string($reason) . "')";
('{$key_details['user_id']}','{$product_details['server_id']}','{$ip}','{$now}','" . ($now + ($allowlength[strtolower($instance->getConfig('allowlength_type'))] * $instance->getConfig('allowlength'))) . "','" . mysqli_real_escape_string($reason) . "')";
mysql_query($sql);

$sql = "UPDATE mod_csfmanager_allow_keys
Expand Down Expand Up @@ -453,7 +453,7 @@ function csfmanager_clientarea($vars)
{
$sql = "SELECT *
FROM mod_csfmanager_allow_keys
WHERE key_hash = '" . mysql_escape_string($key) . "'
WHERE key_hash = '" . mysqli_real_escape_string($key) . "'
AND key_clicks_remained > 0
AND key_expire > '" . time() . "'
AND key_cancelled = 0";
Expand Down Expand Up @@ -806,7 +806,7 @@ function csfmanager_clientarea($vars)
$now = time();

$sql = "INSERT INTO mod_csfmanager_allow (`clientid`,`serverid`,`ip`,`time`,`expiration`,`reason`) VALUES
('{$uid}','{$product_details['server_id']}','{$ip}','{$now}','" . ($now + ($allowlength[strtolower($instance->getConfig('allowlength_type'))] * $instance->getConfig('allowlength'))) . "','" . mysql_escape_string($reason) . "')";
('{$uid}','{$product_details['server_id']}','{$ip}','{$now}','" . ($now + ($allowlength[strtolower($instance->getConfig('allowlength_type'))] * $instance->getConfig('allowlength'))) . "','" . mysqli_real_escape_string($reason) . "')";
mysql_query($sql);
}
else
Expand Down Expand Up @@ -849,13 +849,13 @@ function csfmanager_clientarea($vars)

if($submit)
{
$fullname = trim(mysql_escape_string(csfmanager::request_var('fullname', '')));
$fullname = trim(mysqli_real_escape_string(csfmanager::request_var('fullname', '')));

if($fullname && $email && csfmanager::csfValidateEmail($email))
{
$sql = "SELECT key_id
FROM mod_csfmanager_allow_keys
WHERE key_email = '" . mysql_escape_string($email) . "'
WHERE key_email = '" . mysqli_real_escape_string($email) . "'
AND key_clicks_remained > 0
AND key_expire > '" . time() . "'
AND user_id = '{$product_details['client_id']}'
Expand Down Expand Up @@ -1053,7 +1053,7 @@ function csfmanager_clientarea($vars)
$output['allowedips'][$ip_details['id']]['time'] = date("d/m/Y H:i", $ip_details['time']);
$output['allowedips'][$ip_details['id']]['expiration'] = date("d/m/Y H:i", $ip_details['expiration']);
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$output['allowkeys'] = array();

Expand All @@ -1072,7 +1072,7 @@ function csfmanager_clientarea($vars)

$output['allowkeys'][$key_details['key_id']]['key_expired'] = ($key_details['key_expire'] <= time());
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

break;
}
Expand Down Expand Up @@ -1122,7 +1122,7 @@ function csfmanager_clientarea($vars)
{
$output['services'][] = $product_details;
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$tplfile = 'csfmanagerproducts';
}
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/includes/functions.php
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ function __construct()

$this->config[$config_details['name']] = $config_details['value'];
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$this->_loadLanguage();
}
Expand Down
10 changes: 5 additions & 5 deletions csfmanager/views/allowedlog_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -39,10 +39,10 @@ public function _default()
LEFT JOIN tblservers as s
ON s.id = a.serverid
WHERE a.expiration > '" . time() . "'
" . (trim($search['clientname']) ? "AND UPPER(CONCAT_WS(' ', c.firstname, c.lastname)) LIKE UPPER('%" . mysql_escape_string(trim($search['clientname'])) . "%')" : '') . "
" . (trim($search['clientname']) ? "AND UPPER(CONCAT_WS(' ', c.firstname, c.lastname)) LIKE UPPER('%" . mysqli_real_escape_string(trim($search['clientname'])) . "%')" : '') . "
" . (intval($search['server']) ? "AND s.id = '" . intval($search['server']) . "'" : '') . "
" . (trim($search['ip']) ? "AND a.ip LIKE '%" . mysql_escape_string(trim($search['ip'])) . "%'" : '') . "
" . (trim($search['reason']) ? "AND a.reason LIKE '%" . mysql_escape_string(trim($search['reason'])) . "%'" : '') . "
" . (trim($search['ip']) ? "AND a.ip LIKE '%" . mysqli_real_escape_string(trim($search['ip'])) . "%'" : '') . "
" . (trim($search['reason']) ? "AND a.reason LIKE '%" . mysqli_real_escape_string(trim($search['reason'])) . "%'" : '') . "
ORDER BY a.time DESC";
$result = mysql_query($sql);

Expand All @@ -53,7 +53,7 @@ public function _default()
{
$output['data']['list'][] = array_merge($allow_details, array('time' => date("d/m/Y H:i", $allow_details['time']), 'expiration' => date("d/m/Y H:i", $allow_details['expiration'])));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$output['data']['current_page'] = (($start / $limit) + 1);
$output['data']['total_pages'] = ceil(abs($output['data']['total'] / $limit));
Expand All @@ -72,7 +72,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down
12 changes: 6 additions & 6 deletions csfmanager/views/allowkeys_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,11 @@ public function _default()
ON s.id = k.server_id
WHERE key_id > 0
" . ($status_query ? "AND {$status_query}" : '') . "
" . (trim($search['clientname']) ? "AND UPPER(CONCAT_WS(' ', c.firstname, c.lastname)) LIKE UPPER('%" . mysql_escape_string(trim($search['clientname'])) . "%')" : '') . "
" . (trim($search['clientname']) ? "AND UPPER(CONCAT_WS(' ', c.firstname, c.lastname)) LIKE UPPER('%" . mysqli_real_escape_string(trim($search['clientname'])) . "%')" : '') . "
" . (intval($search['server']) ? "AND s.id = '" . intval($search['server']) . "'" : '') . "
" . (trim($search['recipient']) ? "AND k.key_recipient LIKE '%" . mysql_escape_string(trim($search['recipient'])) . "%'" : '') . "
" . (trim($search['email']) ? "AND k.key_email LIKE '%" . mysql_escape_string(trim($search['email'])) . "%'" : '') . "
" . (trim($search['key']) ? "AND k.key_hash LIKE '%" . mysql_escape_string(trim($search['key'])) . "%'" : '') . "
" . (trim($search['recipient']) ? "AND k.key_recipient LIKE '%" . mysqli_real_escape_string(trim($search['recipient'])) . "%'" : '') . "
" . (trim($search['email']) ? "AND k.key_email LIKE '%" . mysqli_real_escape_string(trim($search['email'])) . "%'" : '') . "
" . (trim($search['key']) ? "AND k.key_hash LIKE '%" . mysqli_real_escape_string(trim($search['key'])) . "%'" : '') . "
ORDER BY k.key_id DESC";
$result = mysql_query($sql);

Expand All @@ -67,7 +67,7 @@ public function _default()
{
$output['data']['list'][] = array_merge($key_details, array('key_expire_date' => date("d/m/Y H:i", $key_details['key_expire'])));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$output['data']['current_page'] = (($start / $limit) + 1);
$output['data']['total_pages'] = ceil(abs($output['data']['total'] / $limit));
Expand All @@ -85,7 +85,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/broadcast_apply.php
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$config_vars = csfmanager::request_var('configVars', array());

Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/broadcast_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/broadcast_selectservers.php
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$templateserver = csfmanager::request_var('templateserver', 0);

Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/broadcast_send.php
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

if(!isset($output['data']['servers'][$server_id]))
{
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/broadcast_setconfig.php
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$templateserver = csfmanager::request_var('templateserver', 0);

Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/firewall_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/firewall_manage.php
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ public function _default()
{
$servers[$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$server_details = $servers[$server_id];

Expand Down
4 changes: 2 additions & 2 deletions csfmanager/views/generatekey_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge($server_details, array('password' => decrypt($server_details['password'], $cc_encryption_hash)));
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

$output['data']['clients'] = array();

Expand All @@ -57,7 +57,7 @@ public function _default()
{
$output['data']['clients'][$client_details['id']] = $client_details;
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down
2 changes: 1 addition & 1 deletion csfmanager/views/settings_default.php
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ public function _default()
{
$output['data']['servers'][$server_details['id']] = array_merge(array('selected' => in_array($server_details['id'], explode(',', $instance->getConfig('servers'))) ? true : false), $server_details);
}
mysql_free_result($result);
mysqli_fetch_assoc($result);

return $output;
}
Expand Down