| 294 | | $query = sprintf("UPDATE articles SET title = '%s', body = '%s', categories_id = %d, active = %d, public = %d, aside = %d, mail_comments = %d, allowanoncomments = %d", |
| 295 | | preg_quote(strip_tags($post["title"]), "'"), |
| 296 | | preg_quote(_strip_tags($post["body"]), "'"), |
| 297 | | $post["categories_id"], |
| 298 | | $post["active"], |
| 299 | | $post["public"], |
| 300 | | $post["aside"], |
| 301 | | $post["mail_comments"], |
| 302 | | $post["allowanoncomments"] |
| | 295 | $query = sprintf("UPDATE articles SET %s = '%s', %s = '%s', %s = %d, %s = %d, %s = %d, %s = %d, %s = %d, %s = %d", |
| | 296 | db_quote("title"), preg_quote(strip_tags($post["title"]), "'"), |
| | 297 | db_quote("body"), preg_quote(_strip_tags($post["body"]), "'"), |
| | 298 | db_quote("categories_id"), $post["categories_id"], |
| | 299 | db_quote("active"), $post["active"], |
| | 300 | db_quote("public"), $post["public"], |
| | 301 | db_quote("aside"), $post["aside"], |
| | 302 | db_quote("mail_comments"), $post["mail_comments"], |
| | 303 | db_quote("allowanoncomments"), $post["allowanoncomments"] |
| 307 | | $query .= sprintf(", last_modified = %d", mktime()); |
| 308 | | $query .= sprintf(", modified_by = %d", $_SESSION["author_id"]); |
| | 308 | $query .= sprintf(", %s = %d", db_quote("last_modified"), mktime()); |
| | 309 | $query .= sprintf(", %s = %d", db_quote("modified_by"), $_SESSION["author_id"]); |
| 313 | | $query .= sprintf(", date = %d", mktime(date("H"), date("i"), date("s"), $post["month"], $post["day"], $post["year"])); |
| | 314 | $query .= sprintf(", %s = %d", db_quote("date"), mktime(date("H"), date("i"), date("s"), $post["month"], $post["day"], $post["year"])); |
| 318 | | $query = "INSERT INTO articles (title, body, authors_id, categories_id, date, active, public, aside, mail_comments, ping_sent, tb_uri, allowanoncomments)"; |
| | 319 | $query = sprintf("INSERT INTO articles (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s)", |
| | 320 | db_quote("title"), db_quote("body"), db_quote("authors_id"), db_quote("categories_id"), db_quote("date"), db_quote("active"), |
| | 321 | db_quote("public"), db_quote("aside"), db_quote("mail_comments"), db_quote("ping_sent"), db_quote("tb_uri"), db_quote("allowanoncomments") |
| | 322 | ); |
| 335 | | $sql = sprintf("SELECT id FROM articles WHERE title = '%s' AND body = '%s' AND authors_id = %d AND categories_id = %d", |
| 336 | | preg_quote(strip_tags($post["title"]), "'"), |
| 337 | | preg_quote(_strip_tags($post["body"]), "'"), |
| | 339 | $sql = sprintf("SELECT id FROM articles WHERE %s = '%s' AND %s = '%s' AND authors_id = %d AND categories_id = %d", |
| | 340 | db_quote("title"), preg_quote(strip_tags($post["title"]), "'"), |
| | 341 | db_quote("body"), preg_quote(_strip_tags($post["body"]), "'"), |
| 487 | | $query = sprintf("UPDATE categories SET \"name\" = '%s', \"desc\" = '%s', active = %d, public = %d WHERE id = %d", |
| 488 | | preg_quote(strip_tags($cat["name"]), "'"), |
| 489 | | preg_quote(strip_tags($cat["description"]), "'"), |
| 490 | | $cat["active"], |
| 491 | | $cat["public"], |
| | 491 | $query = sprintf("UPDATE categories SET %s = '%s', %s = '%s', %s = %d, %s = %d WHERE id = %d", |
| | 492 | db_quote("name"), preg_quote(strip_tags($cat["name"]), "'"), |
| | 493 | db_quote("desc"), preg_quote(strip_tags($cat["description"]), "'"), |
| | 494 | db_quote("active"), $cat["active"], |
| | 495 | db_quote("public"), $cat["public"], |
| 495 | | $query = sprintf("INSERT INTO categories (\"name\", \"desc\", active, public) VALUES ('%s', '%s', %d, %d)", |
| | 499 | $query = sprintf("INSERT INTO categories (%s, %s, %s, %s) VALUES ('%s', '%s', %d, %d)", |
| | 500 | db_quote("name"), db_quote("desc"), db_quote("active"), db_quote("public"), |
| 603 | | $query = sprintf("UPDATE acronyms SET acronym = '%s', description = '%s' WHERE id = %d", |
| 604 | | preg_quote(strip_tags($acro["acronym"]), "'"), |
| 605 | | preg_quote(_strip_tags($acro["description"]), "'"), |
| | 608 | $query = sprintf("UPDATE acronyms SET %s = '%s', %s = '%s' WHERE id = %d", |
| | 609 | db_quote("acronym"), preg_quote(strip_tags($acro["acronym"]), "'"), |
| | 610 | db_quote("description"), preg_quote(_strip_tags($acro["description"]), "'"), |
| 763 | | $query = sprintf("UPDATE authors SET fullname = '%s', email = '%s', website = '%s', active = %d", |
| 764 | | preg_quote(strip_tags($author["fullname"]), "'"), |
| 765 | | preg_quote(strip_tags($author["email"]), "'"), |
| 766 | | preg_quote(strip_tags($author["website"]), "'"), |
| 767 | | $author["active"] |
| | 769 | $query = sprintf("UPDATE authors SET %s = '%s', %s = '%s', %s = '%s', %s = %d", |
| | 770 | db_quote("fullname"), preg_quote(strip_tags($author["fullname"]), "'"), |
| | 771 | db_quote("email"), preg_quote(strip_tags($author["email"]), "'"), |
| | 772 | db_quote("website"), preg_quote(strip_tags($author["website"]), "'"), |
| | 773 | db_quote("active"), $author["active"] |
| 774 | | $query = sprintf("INSERT INTO authors (password, fullname, email, website, login, active) VALUES ('%s', '%s', '%s', '%s', '%s', %d)", |
| | 780 | $query = sprintf("INSERT INTO authors (%s, %s, %s, %s, %s, %s) VALUES ('%s', '%s', '%s', '%s', '%s', %d)", |
| | 781 | db_quote("password"), db_type("fullname"), db_type("email"), db_quote("website"), db_quote("login"), db_quote("active"), |
| 930 | | $query = sprintf("UPDATE blog_users SET realname = '%s', email = '%s', website = '%s', active = %d", |
| 931 | | preg_quote(strip_tags($user["realname"]), "'"), |
| 932 | | preg_quote(strip_tags($user["email"]), "'"), |
| 933 | | preg_quote(strip_tags($user["website"]), "'"), |
| 934 | | $user["active"] |
| | 937 | $query = sprintf("UPDATE blog_users SET %s = '%s', %s = '%s', %s = '%s', %s = %d", |
| | 938 | db_quote("realname"), preg_quote(strip_tags($user["realname"]), "'"), |
| | 939 | db_quote("email"), preg_quote(strip_tags($user["email"]), "'"), |
| | 940 | db_quote("website"), preg_quote(strip_tags($user["website"]), "'"), |
| | 941 | db_quote("active"), $user["active"] |
| 941 | | $query = sprintf("INSERT INTO blog_users (password, realname, email, website, username, active) VALUES ('%s', '%s', '%s', '%s', '%s', %d)", |
| | 948 | $query = sprintf("INSERT INTO blog_users (%s, %s, %s, %s, %s, %s) VALUES ('%s', '%s', '%s', '%s', '%s', %d)", |
| | 949 | db_quote("password"), db_quote("realname"), db_quote("email"), db_quote("website"), db_quote("username"), db_quote("active"), |