From: Scott P. <wht...@us...> - 2007-09-11 22:22:29
|
Update of /cvsroot/helpmeict/Helpdesk In directory sc8-pr-cvs17:/tmp/cvs-serv23259 Modified Files: find.php Log Message: Missed some items on cleanup from last checkin. Index: find.php =================================================================== RCS file: /cvsroot/helpmeict/Helpdesk/find.php,v retrieving revision 1.15 retrieving revision 1.16 diff -C2 -d -r1.15 -r1.16 *** find.php 11 Sep 2007 15:51:30 -0000 1.15 --- find.php 11 Sep 2007 22:22:26 -0000 1.16 *************** *** 314,323 **** foreach ($site as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 314,318 ---- foreach ($site as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 332,341 **** foreach ($reportedby as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 327,331 ---- foreach ($reportedby as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 350,359 **** foreach ($createdby as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 340,344 ---- foreach ($createdby as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 377,386 **** foreach ($assignedto as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 362,366 ---- foreach ($assignedto as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 395,404 **** foreach ($level as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 375,379 ---- foreach ($level as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 413,422 **** foreach ($priority as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 388,392 ---- foreach ($priority as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 431,440 **** foreach ($status as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 401,405 ---- foreach ($status as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 451,460 **** foreach ($category as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 416,420 ---- foreach ($category as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; *************** *** 469,478 **** foreach ($detail as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! if (!get_magic_quotes_gpc()) { ! $sql .= addslashes(htmlentities(strip_tags($record), ENT_QUOTES)); ! } ! else { ! $sql .= $record; ! } } $sql .= ') AND '; --- 429,433 ---- foreach ($detail as $record) { if ($flag == 0) { $flag = 1; } else { $sql .= ','; } ! $sql .= htmlentities(strip_tags($record), ENT_QUOTES); } $sql .= ') AND '; |