![]() |
alright, just uploaded a version that cleans get and post vars where needed.
|
Code:
$_POST = array_map('mysql_real_escape_string', $_POST); Code:
function clean($value){ |
Don't forget some xss cleaning functions
Code:
// Prep user input for storage - XSS cleanup |
this is a variation of what I use in some other scripts which I just put into this one:
Code:
foreach($_POST as $varName => $value) |
1) can you have the videos higher up the page so i dont have to scroll down?
2) can the 300x250 adspace be edited to 250x250 by webmaster? |
Just so you know, your template does not look right under firefox
|
you should get icq
|
Quote:
2) thats easy enough, go into ads/250x250.tpl I actually don't see 300x250 ads, 250x250 is used everywhere I'm seeing. |
so... is the new version more secure now?
|
Quote:
|
Quote:
:thumbsup |
I'll have an embed import for a few top tube sites ready to roll out tomorrow sometime ;) after that I'm going to focus on sponsor content to get an addon out for supporting those.
|
looks sweet how do I get a copy of this?
|
Still not really secure, youve just thrown in a auto convert of the _GET and _POST to local vars which will still be incorrect as you clean then once with
get_magic_quotes_gpc() check then use the initial raw data to do the mysql_real_escape_string() clean. But then, if the value is an integer, its not cleaned at all, so the raw data is still flowing through. Make use of (int) or intval() if you know the variable you want HAS to be an integer. |
Quote:
https://gfy.com/14077683-post23.html |
bump whats the latest?
|
updates please?
|
bumpppo :)
|
bump coz he seems to care more about Garmin Mobile XT phone replacing GPS :1orglaugh
|
bizzump yo :disgust
|
:):pimp:(:disgust:mad::1orglaugh
|
Quote:
This system talked about in this thread is FREE, what makes me $$$ is obviously my top priority. I'll work this in when I have time. I'm trying to finish off a custom CMS this week and then I have another one on my schedule right behind that |
Quote:
does the free script even work as is? |
last I checked it was working as is...
I have a '68 mustang that took me too long to get just the way I wanted it and I'm having some financial trouble but I think it would kill me to have to sell it so I have to whore myself out for a quick buck |
good luck m8 :)
|
Quote:
jealousy creeps in |
You site been hacked? http://demo.fastfreemedia.com/
|
Quote:
|
notice that: http://adult.fastfreemedia.com/ didn't get touched... you can bet the same person who hit the other link TRIED to get adult. too but failed.
|
i get this error in rating.php when i click rate
Warning: mysql_real_escape_string(): Can't connect to local MySQL server through socket '/tmp/mysql.sock' (2) |
Tube sites are overrated.
|
All times are GMT -7. The time now is 03:24 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123