diff --git a/src/messenger/webim/libs/expand.php b/src/messenger/webim/libs/expand.php index 5e596403..4d44949b 100644 --- a/src/messenger/webim/libs/expand.php +++ b/src/messenger/webim/libs/expand.php @@ -71,8 +71,6 @@ function expand_var($matches) { return form_value($var); } else if($prefix == 'page:') { return $page[$var]; - } else if($prefix == 'print:') { - return htmlspecialchars($page[$var]); } else if($prefix == 'if:' || $prefix == 'else:' || $prefix == 'endif:' || $prefix == 'ifnot:') { return ""; } diff --git a/src/messenger/webim/operator/ban.php b/src/messenger/webim/operator/ban.php index b1ee86a0..de3dc48d 100644 --- a/src/messenger/webim/operator/ban.php +++ b/src/messenger/webim/operator/ban.php @@ -59,15 +59,15 @@ if( isset($_POST['address']) ) { $query = sprintf( "insert into chatban (dtmcreated,dtmtill,address,comment) values (CURRENT_TIMESTAMP,%s,'%s','%s')", "FROM_UNIXTIME($utime)", - quote_smart($address,$link), - quote_smart($comment,$link)); + mysql_real_escape_string($address,$link), + mysql_real_escape_string($comment,$link)); perform_query($query,$link); } else { $query = sprintf( "update chatban set dtmtill = %s,address = '%s',comment = '%s' where banid = $banId", "FROM_UNIXTIME($utime)", - quote_smart($address,$link), - quote_smart($comment,$link)); + mysql_real_escape_string($address,$link), + mysql_real_escape_string($comment,$link)); perform_query($query,$link); } mysql_close($link);