Changeset 2087 in ExiteCMS for trunk/register.php


Ignore:
Timestamp:
12/01/08 12:12:32 (3 years ago)
Author:
WanWizard
Message:

fixed bug in registration when using single quotes in the user fullname when registering
fixed several bugs in user activation

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/register.php

    r2086 r2087  
    2222 
    2323// do we want extensive email checks? 
    24 define('CHECK_EMAIL', true); 
     24define('CHECK_EMAIL', false); 
    2525 
    2626// temp storage for template variables 
     
    191191                        "user_hide_email" => isNum($_POST['user_hide_email']) ? $_POST['user_hide_email'] : "1" 
    192192                    )); 
    193                     $result = dbquery("INSERT INTO ".$db_prefix."new_users (user_code, user_email, user_datestamp, user_info) VALUES('$user_code', '".$email."', '".time()."', '$user_info')"); 
     193                    $result = dbquery("INSERT INTO ".$db_prefix."new_users (user_code, user_email, user_datestamp, user_info) VALUES('$user_code', '".$email."', '".time()."', '".mysql_real_escape_string($user_info)."')"); 
    194194                    $variables['message'] = $locale['454']; 
    195195                    $title = $locale['400']; 
     
    207207                    $variables['message'] = $locale['453']; 
    208208                    // send the webmaster a PM that an account needs to be activated 
    209                     $result = dbquery("INSERT INTO ".$db_prefix."pm (pm_subject, pm_message, pm_recipients, pm_size, pm_datestamp) VALUES ('".$locale['509']."', '".mysql_escape_string(sprintf($locale['510'], $username))."', '1', '100', '".time()."')"); 
     209                    $result = dbquery("INSERT INTO ".$db_prefix."pm (pm_subject, pm_message, pm_recipients, pm_size, pm_datestamp) VALUES ('".$locale['509']."', '".mysql_real_escape_string(sprintf($locale['510'], $username))."', '1', '100', '".time()."')"); 
    210210                    if ($result) { 
    211211                        $pm_id = mysql_insert_id(); 
Note: See TracChangeset for help on using the changeset viewer.