############################################################## ## MOD Title: Approve_Mod_Patch 1.0.9 to 1.0.10 ## MOD Author: Aceman < phpbbmods@synace.com > (Mike Dawidowicz) http://www.synace.com ## MOD Description: This Patches the Approve_Mod from version 1.0.9 to version 1.0.10 ## MOD Version: 1.0.0 ## ## Installation Level: Easy ## Installation Time: 5 Minutes ## Files To Edit: admin/admin_approve.php ############################################################## ## For Security Purposes, Please Check: http://www.phpbb.com/mods/ for the ## latest version of this MOD. Downloading this MOD from other sites could cause malicious code ## to enter into your phpBB Forum. As such, phpBB will not offer support for MOD's not offered ## in our MOD-Database, located at: http://www.phpbb.com/mods/ ############################################################## ## Author Notes: ## ## Approve_Mod 1.0.10 Released: April 12, 2005. ## Please see README.html from the distribution for further information. You may also view ## the release thread on phpBB.com at: ## http://www.phpbb.com/phpBB/viewtopic.php?t=122005 ############################################################## ## MOD History: ## ## 2005-04-12 - Version 1.0.0 ## - Fixed GET/POST vars in admin_approve, added SQL injection prevention ## ############################################################## ## Before Adding This MOD To Your Forum, You Should Back Up All Files Related To This MOD ############################################################## # #-----[ OPEN ]------------------------------------------ # admin/admin_approve.php # #-----[ FIND ]------------------------------------------ # $mode = ($HTTP_GET_VARS['mode']) ? $HTTP_GET_VARS['mode'] : $HTTP_POST_VARS['mode']; # #-----[ AFTER, ADD ]------------------------------------------ # $s = ($HTTP_GET_VARS['s']) ? $HTTP_GET_VARS['s'] : $HTTP_POST_VARS['s']; $p = ($HTTP_GET_VARS['p']) ? $HTTP_GET_VARS['p'] : $HTTP_POST_VARS['p']; $id =($HTTP_GET_VARS['id']) ? $HTTP_GET_VARS['id'] : $HTTP_POST_VARS['id']; $submit = ( !empty($HTTP_POST_VARS['submit']) ) ? true : false; # #-----[ FIND ]------------------------------------------ # WHERE username = '" . $HTTP_POST_VARS['username'] . "'"; # #-----[ REPLACE WITH ]------------------------------------------ # WHERE username = '" . ( get_magic_quotes_gpc() ? $HTTP_POST_VARS['username'] : addslashes($HTTP_POST_VARS['username']) ) . "'"; # #-----[ FIND ]------------------------------------------ # WHERE username = '" . $HTTP_POST_VARS['username'] . "'"; # #-----[ REPLACE WITH ]------------------------------------------ # WHERE username = '" . ( get_magic_quotes_gpc() ? $HTTP_POST_VARS['username'] : addslashes($HTTP_POST_VARS['username']) ) . "'"; # #-----[ SAVE/CLOSE ALL FILES ]------------------------------------------ # # EoM