Changeset 2839 for branches/2.0/admin


Ignore:
Timestamp:
Nov 7, 2008, 2:56:00 PM (15 years ago)
Author:
patdenice
Message:

merge -c2838 from trunk to branch 2.0

  • improve 1.3.1 upgrade (automatic write in mysql.inc.php).
  • translate 1.3.1 upgrade informations messages.
  • security fix in upgrade login.
File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/2.0/admin/include/functions_upgrade.php

    r2837 r2839  
    137137  global $conf, $page;
    138138
     139  if(!get_magic_quotes_gpc())
     140  {
     141    $username = mysql_real_escape_string($username);
     142  }
     143
    139144  if (version_compare($current_release, '1.5.0', '<'))
    140145  {
    141146    $query = '
    142147SELECT password, status
    143 FROM '.PREFIX_TABLE.'users
     148FROM '.USERS_TABLE.'
    144149WHERE username = "'.$username.'"
    145150;';
     
    150155SELECT u.password, ui.status
    151156FROM '.$conf['users_table'].' AS u
    152 INNER JOIN '.PREFIX_TABLE.'user_infos AS ui
    153 ON u.id = ui.user_id
     157INNER JOIN '.USER_INFOS_TABLE.' AS ui
     158ON u.'.$conf['user_fields']['id'].'=ui.user_id
    154159WHERE '.$conf['user_fields']['username'].'="'.$username.'"
    155160;';
Note: See TracChangeset for help on using the changeset viewer.