diff options
Diffstat (limited to 'php/index-list.php')
-rw-r--r-- | php/index-list.php | 25 |
1 files changed, 12 insertions, 13 deletions
diff --git a/php/index-list.php b/php/index-list.php index 1705ee6..1b158b7 100644 --- a/php/index-list.php +++ b/php/index-list.php @@ -7,25 +7,24 @@ require_once('./cfg/init.php'); require_once(LIB.'/auth.php'); // auth functions require_once(LIB.'/forms.php'); // form library -require_once(LIB.'/list.php'); // list library error_reporting(E_GET); if (!empty($_GET['os'])&&!empty($_GET['product'])) { // clean in os and product strings - $os_name = mysql_real_escape_string(trim(strtolower($_GET['os']))); - $product_name = mysql_real_escape_string(trim(strtolower($_GET['product']))); + $os_name = trim(strtolower(filter_input(INPUT_GET,'os'))); + $product_name = trim(strtolower(filter_input(INPUT_GET,'product'))); // get os and product IDs - $os_id = db_name_to_id('mirror_os','os_id','os_name',$os_name); - $product_id = db_name_to_id('mirror_products','product_id','product_name',$product_name); + $os_id = DB::name_to_id('mirror_os','os_id','os_name',$os_name); + $product_id = DB::name_to_id('mirror_products','product_id','product_name',$product_name); } if (!empty($_GET['os_id'])&&!empty($_GET['product_id'])) { - $os_id = intval($_GET['os_id']); - $product_id = intval($_GET['product_id']); + $os_id = intval(filter_input(INPUT_GET, 'os_id', FILTER_SANITIZE_NUMBER_INT)); + $product_id = intval(filter_input(INPUT_GET, 'product_id', FILTER_SANITIZE_NUMBER_INT)); } if (!empty($os_id)&&!empty($product_id)) { - $mirrors = db_get(" + $mirrors = DB::get(" SELECT DISTINCT mirror_baseurl, location_path FROM @@ -39,13 +38,13 @@ if (!empty($os_id)&&!empty($product_id)) { ON mirror_location_mirror_map.location_id = mirror_locations.location_id WHERE - mirror_locations.os_id = {$os_id} AND - mirror_locations.product_id = {$product_id} AND + mirror_locations.os_id = ? AND + mirror_locations.product_id = ? AND mirror_location_mirror_map.location_active = '1' AND mirror_mirrors.mirror_active = '1' ORDER BY mirror_rating DESC, mirror_baseurl - "); + ", PDO::FETCH_ASSOC, [$os_id, $product_id]); header("Content-type: text/plain;"); foreach ($mirrors as $mirror) { @@ -68,13 +67,13 @@ if (!empty($os_id)&&!empty($product_id)) { form_start('list','list','get','./index-list.php'); echo '<div>'; form_label('Product', 'product','label-small'); - form_select('product_id','product','',mirror_get_products_select(),$_GET['product_id']); + form_select('product_id','product','',Mirror::get_products_select(),$_GET['product_id']); echo ' [<a href="./products.php">edit products</a>]'; echo '</div><br />'; echo '<div>'; form_label('OS', 'os','label-small'); - form_select('os_id','os','',mirror_get_oss_select(),$_GET['os_id']); + form_select('os_id','os','',Mirror::get_oss_select(),$_GET['os_id']); echo ' [<a href="./os.php">edit operating systems</a>]'; echo '</div><br />'; form_submit('submit','','button1','Update'); |