|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 65
Members: 0
Total: 65
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
Posted: Wed Sep 01, 2004 10:02 am |
|
|
shmk |
Active user |
|
|
Joined: Jul 22, 2004 |
Posts: 25 |
|
|
|
|
|
|
|
I'm back !
Is possible echo smiles without make some security holes ?
To echo smiles i made this piece of code but I think is not so secure
Code: | $sqlsm = "SELECT code, smile_url FROM ".$prefix."_bbsmilies";
$resultsm = $db->sql_query($sqlsm);
while($rowsm = $db->sql_fetchrow($resultsm)) {
$sm_url = "<img src=\"modules/Forums/images/smiles/$rowsm[1]\"></img>";
$comment = str_replace($rowsm[0], $sm_url, $comment);
}
echo "<td align=left>$comment</td>"; |
Can you help me ? |
|
|
|
|
|
|
|
|
Posted: Wed Sep 01, 2004 7:17 pm |
|
|
madman |
Active user |
|
|
Joined: May 24, 2004 |
Posts: 46 |
|
|
|
|
|
|
|
And I'm waiting.
shmk wrote: | Is possible echo smiles without make some security holes ? To echo smiles i made this piece of code but I think is not so secure |
I didn't see what security holes you mentioned on your code. By the way, the code above won't work as expected.
Try this one:
Code: | $sqlsm = "SELECT code, smile_url FROM ".$prefix."_bbsmilies";
if ($resultsm = $db->sql_query($sqlsm))
{
while(list($code, $url) = $db->sql_fetchrow($resultsm))
{
$sm_url = "<img src=\"modules/Forums/images/smiles/$url\" />";
$comment = str_replace($code, $sm_url, $comment);
}
}
echo "<td align=left>$comment</td>"; |
shmk wrote: | Can you help me ? |
Ok. |
|
_________________ ch88rs,
madman |
|
|
|
|
www.waraxe.us Forum Index -> Php
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 2 of 2
Goto page Previous1, 2
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|