|
From: Jon O. <jon...@us...> - 2006-06-17 20:49:05
|
Update of /cvsroot/mxbb/mx_newssuite In directory sc8-pr-cvs7.sourceforge.net:/tmp/cvs-serv5967/modules/mx_newssuite Modified Files: news.php Log Message: security Index: news.php =================================================================== RCS file: /cvsroot/mxbb/mx_newssuite/news.php,v retrieving revision 1.14 retrieving revision 1.15 diff -C2 -d -r1.14 -r1.15 *** news.php 5 Apr 2006 22:35:24 -0000 1.14 --- news.php 17 Jun 2006 20:49:02 -0000 1.15 *************** *** 9,12 **** --- 9,17 ---- */ + if( !defined('IN_PORTAL') || !is_object($mx_block)) + { + die("Hacking attempt"); + } + $newssuite_config = ''; $category_nav_mode = ''; *************** *** 74,78 **** $news_sort_method_pin = $newssuite_config['news_mode_pinning'] == '1'; // order by type $news_sort_par = $newssuite_config['news_sort_par']; // ASC, DESC ! $news_filter_time = $newssuite_config['news_filter_time']; // no limit, last day, 2 days, 3 days, week, 2 weeks, 3 weeks, month, 2 months, 3 months, 6 months, i year, // --- 79,83 ---- $news_sort_method_pin = $newssuite_config['news_mode_pinning'] == '1'; // order by type $news_sort_par = $newssuite_config['news_sort_par']; // ASC, DESC ! $news_filter_time = $newssuite_config['news_filter_time']; // no limit, last day, 2 days, 3 days, week, 2 weeks, 3 weeks, month, 2 months, 3 months, 6 months, i year, // *************** *** 89,108 **** { case 'Default_Block_Mode': ! $template->set_filenames( array( 'body' => 'news_body.tpl' ) ); break; case 'Newspaper_Mode': ! $template->set_filenames( array( 'body' => 'news_body_paper.tpl' ) ); break; case 'Category_Nav_Mode': ! $template->set_filenames( array( 'body' => 'news_body_nav.tpl' ) ); $category_nav_mode = true; break; default: ! $template->set_filenames( array( 'body' => 'news_body.tpl' ) ); --- 94,113 ---- { case 'Default_Block_Mode': ! $template->set_filenames( array( 'body' => 'news_body.tpl' ) ); break; case 'Newspaper_Mode': ! $template->set_filenames( array( 'body' => 'news_body_paper.tpl' ) ); break; case 'Category_Nav_Mode': ! $template->set_filenames( array( 'body' => 'news_body_nav.tpl' ) ); $category_nav_mode = true; break; default: ! $template->set_filenames( array( 'body' => 'news_body.tpl' ) ); *************** *** 113,120 **** { $template->assign_block_vars( "switch_standard_title", array() ); ! } // Assign some basic language variables ! // $template->assign_vars( array( 'BLOCK_SIZE' => $block_size, 'BLOCK_ID' => $block_id, --- 118,125 ---- { $template->assign_block_vars( "switch_standard_title", array() ); ! } // Assign some basic language variables ! // $template->assign_vars( array( 'BLOCK_SIZE' => $block_size, 'BLOCK_ID' => $block_id, *************** *** 129,134 **** 'L_NEWS_NONE' => $lang['News_none'], ! 'NEWS_BLOCK_BORDER_STYLE' => $news_block_border_style ! ) ); --- 134,139 ---- 'L_NEWS_NONE' => $lang['News_none'], ! 'NEWS_BLOCK_BORDER_STYLE' => $news_block_border_style ! ) ); *************** *** 143,151 **** $news_type_select_data = array(); $news_type_select_data[$item_types_all] = array(); ! for( $z = 0; $z < ( count( $item_types_array ) ); $z++ ) { $news_type_select_data[$item_types_array[$z]] = array(); ! } } --- 148,156 ---- $news_type_select_data = array(); $news_type_select_data[$item_types_all] = array(); ! for( $z = 0; $z < ( count( $item_types_array ) ); $z++ ) { $news_type_select_data[$item_types_array[$z]] = array(); ! } } |