From 7d1443f0b59b726a678e9aafa8bbff66f5ef2808 Mon Sep 17 00:00:00 2001 From: Leonard Jonathan Oh Date: Sun, 10 Mar 2024 04:06:08 +0000 Subject: [PATCH] Fix (bf2sclone): Fix Search page to work correctly --- src/bf2sclone/search.inc.php | 1 + src/bf2sclone/template/search.php | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/src/bf2sclone/search.inc.php b/src/bf2sclone/search.inc.php index 1d03d2af..f71d5b71 100644 --- a/src/bf2sclone/search.inc.php +++ b/src/bf2sclone/search.inc.php @@ -2,6 +2,7 @@ function getSearchResults($SEARCHVALUE) { + $SEARCHVALUE = mysqli_real_escape_string($GLOBALS['link'], $SEARCHVALUE); include(ROOT . DS . 'queries'. DS .'getPIDList.php'); // imports the correct sql statement $result = mysqli_query($GLOBALS['link'], $query) or die('Query failed: ' . mysqli_error($GLOBALS['link'])); $data = array(); diff --git a/src/bf2sclone/template/search.php b/src/bf2sclone/template/search.php index affe08e4..eb1fcebf 100644 --- a/src/bf2sclone/template/search.php +++ b/src/bf2sclone/template/search.php @@ -50,7 +50,7 @@ @@ -78,7 +78,7 @@ $template .= ' - ' . (RANKING_PIDS_AS_NAMES ? $searchresults[$i]['id'] : esc_attr($searchresults[$i]['name'])) . '  + ' . esc_attr(RANKING_PIDS_AS_NAMES ? $searchresults[$i]['id'] : $searchresults[$i]['name']) . '  '.$searchresults[$i]['score'].'