diff --git a/core/core.php b/core/core.php index af5a2d2..ac3b90a 100644 --- a/core/core.php +++ b/core/core.php @@ -10,8 +10,8 @@ class Core { - public $version = '4.1.2'; - public $version_date = '2017-04-02, 15:41'; + public $version = '4.1.3'; + public $version_date = '2017-09-18, 10:21'; public $db_version = '4.1.0'; private $conf; diff --git a/inc/admin/script_files/admin.donate.php b/inc/admin/script_files/admin.donate.php index 07b0b7c..110cab4 100644 --- a/inc/admin/script_files/admin.donate.php +++ b/inc/admin/script_files/admin.donate.php @@ -20,7 +20,7 @@ function editPkg() { global $DB, $lang; $DB->query("UPDATE `mw_donate_packages` SET - `desc`='".$_POST['desc']."', + `desc`='".$DB->real_escape_string($_POST['desc'])."', `cost`='".$_POST['cost']."', `points`='".$_POST['points']."' WHERE `id`='".$_GET['id']."' @@ -43,7 +43,7 @@ function addPkg() `cost`, `points`) VALUES( - '".$_POST['desc']."', + '".$DB->real_escape_string($_POST['desc'])."', '".$_POST['cost']."', '".$_POST['points']."' ) diff --git a/inc/admin/script_files/admin.faq.php b/inc/admin/script_files/admin.faq.php index bc4e6bf..56c8a5a 100644 --- a/inc/admin/script_files/admin.faq.php +++ b/inc/admin/script_files/admin.faq.php @@ -20,8 +20,8 @@ function editFaq() { global $DB, $Core, $lang; $DB->query("UPDATE `mw_faq` SET - `question`='".$_POST['question']."', - `answer`='".$_POST['answer']."' + `question`='".$DB->real_escape_string($_POST['question'])."', + `answer`='".$DB->real_escape_string($_POST['answer'])."' WHERE `id`='".$_GET['id']."' "); @@ -45,8 +45,8 @@ function addFaq() `question`, `answer`) VALUES( - '".$_POST['question']."', - '".$_POST['answer']."' + '".$DB->real_escape_string($_POST['question'])."', + '".$DB->real_escape_string($_POST['answer'])."' ) "); diff --git a/inc/admin/script_files/admin.fplinks.php b/inc/admin/script_files/admin.fplinks.php index 0129c54..97f3398 100644 --- a/inc/admin/script_files/admin.fplinks.php +++ b/inc/admin/script_files/admin.fplinks.php @@ -41,7 +41,7 @@ function editLink() global $DB, $Core, $lang; $DB->query("UPDATE `mw_menu_items` SET `menu_id`='".$_POST['menu_id']."', - `link_title`='".$_POST['link_title']."', + `link_title`='".$DB->real_escape_string($_POST['link_title'])."', `link`='".$_POST['link']."', `guest_only`='".$_POST['guest_only']."', `account_level`='".$_POST['account_level']."' @@ -70,7 +70,7 @@ function addLink() `account_level`) VALUES( '".$_POST['menu_id']."', - '".$_POST['link_title']."', + '".$DB->real_escape_string($_POST['link_title'])."', '".$_POST['link']."', '".$_POST['guest_only']."', '".$_POST['account_level']."') diff --git a/update/update_list.txt b/update/update_list.txt index ec9790f..f0f80cd 100644 --- a/update/update_list.txt +++ b/update/update_list.txt @@ -1,3 +1,4 @@ +4.1.3,4.1.0 4.1.2,4.1.0 4.1.1,4.1.0 4.1.0,4.1.0