diff --git a/accounts.php b/accounts.php index f1daa624..f078e396 100644 --- a/accounts.php +++ b/accounts.php @@ -3,7 +3,7 @@ require_once("inc_all.php"); if (!empty($_GET['sb'])) { - $sb = strip_tags(mysqli_real_escape_string($mysqli, $_GET['sb'])); + $sb = sanitizeInput($_GET['sb']); } else { $sb = "account_name"; } @@ -32,7 +32,7 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()"));
- +
@@ -53,23 +53,23 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); diff --git a/check_login.php b/check_login.php index da7ba6de..f44ff076 100644 --- a/check_login.php +++ b/check_login.php @@ -23,8 +23,8 @@ if (!isset($_SESSION['logged']) || !$_SESSION['logged']) { } // User IP & UA -$session_ip = strip_tags(mysqli_real_escape_string($mysqli, getIP())); -$session_user_agent = strip_tags(mysqli_real_escape_string($mysqli, $_SERVER['HTTP_USER_AGENT'])); +$session_ip = sanitizeInput(getIP()); +$session_user_agent = sanitizeInput($_SERVER['HTTP_USER_AGENT']); $session_user_id = $_SESSION['user_id']; diff --git a/client_document_edit_modal.php b/client_document_edit_modal.php index 594b1899..ee2f134f 100644 --- a/client_document_edit_modal.php +++ b/client_document_edit_modal.php @@ -9,6 +9,7 @@
+