Advertisement
Guest User

Untitled

a guest
May 7th, 2017
66
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.26 KB | None | 0 0
  1. --- patch4.php.orig 2009-08-16 16:31:34.000000000 -0700
  2. +++ patch4.php 2009-08-16 16:32:49.000000000 -0700
  3. @@ -15,7 +15,7 @@
  4. {
  5. if( isset( $_COOKIE['username'] ) && isset( $_COOKIE['password'] ) )
  6. {
  7. - $query = "SELECT * FROM `members` WHERE username = '" . $_COOKIE['username'] . "' AND password = '" . $_COOKIE['password'] . "'";
  8. + $query = "SELECT * FROM `members` WHERE username = '" . mysql_real_escape_string($_COOKIE['username']) . "' AND password = '" . mysql_real_escape_string($_COOKIE['password']) . "'";
  9. $res = mysql_query( $query ) or die( "Query: " . $query . " failed." );
  10. $rows = mysql_num_rows( $res );
  11. if( !$rows )
  12. @@ -24,8 +24,8 @@
  13. }
  14. if( isset( $_POST['update'] ) )
  15. {
  16. - $pass = addslashes( $_POST['new_pass'] );
  17. - $update = "UPDATE members SET password = '" . $pass . "' WHERE username = '" . $_COOKIE['username'];
  18. + $pass = mysql_real_escape_string( $_POST['new_pass'] );
  19. + $update = "UPDATE members SET password = '" . $pass . "' WHERE username = '" . mysql_real_escape_string($_COOKIE['username']);
  20. mysql_query( $update ) or die( "Unable to update your password, please try again!" );
  21. }
  22. else
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement