diff --git a/includes/account.php b/includes/account.php index d14e27d..6dacf2d 100644 --- a/includes/account.php +++ b/includes/account.php @@ -120,7 +120,7 @@ function buildSubjectFromSession() { showfooter(); exit; } - if(trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newemail']))) == "") + if(trim(mysql_real_escape_string(stripslashes($_REQUEST['newemail']))) == "") { showheader(_("My CAcert.org Account!")); printf(_("Not a valid email address. Can't continue.")); @@ -128,7 +128,7 @@ function buildSubjectFromSession() { exit; } $oldid=0; - $_REQUEST['email'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newemail']))); + $_REQUEST['email'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['newemail']))); if(check_email_exists($_REQUEST['email'])==true) { showheader(_("My CAcert.org Account!")); @@ -152,8 +152,8 @@ function buildSubjectFromSession() { } $hash = make_hash(); $query = "insert into `email` set `email`='".$_REQUEST['email']."',`memid`='".intval($_SESSION['profile']['id'])."',`created`=NOW(),`hash`='$hash'"; - mysqli_query($_SESSION['mconn'],$query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + mysql_query($query); + $emailid = mysql_insert_id(); $body = _("Below is the link you need to open to verify your email address. Once your address is verified you will be able to start issuing certificates to your heart's content!")."\n\n"; $body .= "http://".$_SESSION['_config']['normalhostname']."/verify.php?type=email&emailid=$emailid&hash=$hash\n\n"; @@ -172,15 +172,15 @@ function buildSubjectFromSession() { $id = 2; $emailid = intval($_REQUEST['emailid']); $query = "select * from `email` where `id`='$emailid' and `memid`='".intval($_SESSION['profile']['id'])."' and `hash` = '' and `deleted`=0"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { showheader(_("Error!")); echo _("You currently don't have access to the email address you selected, or you haven't verified it yet."); showfooter(); exit; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $body = sprintf(_("Hi %s,"),$_SESSION['profile']['fname'])."\n\n"; $body .= _("You are receiving this email because you or someone else ". "has changed the default email on your account.")."\n\n"; @@ -191,8 +191,8 @@ function buildSubjectFromSession() { "support@cacert.org", "", "", "CAcert Support"); $_SESSION['profile']['email'] = $row['email']; - $query = "update `users` set `email`='".mysqli_real_escape_string($_SESSION['mconn'], $row['email'])."' where `id`='".intval($_SESSION['profile']['id'])."'"; - mysqli_query($_SESSION['mconn'],$query); + $query = "update `users` set `email`='".mysql_real_escape_string($row['email'])."' where `id`='".intval($_SESSION['profile']['id'])."'"; + mysql_query($query); showheader(_("My CAcert.org Account!")); printf(_("Your default email address has been updated to '%s'."), sanitizeHTML($row['email'])); showfooter(); @@ -216,11 +216,11 @@ function buildSubjectFromSession() { } $id = intval($id); $query = "select * from `email` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."' and - `email`!='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['profile']['email'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) > 0) + `email`!='".mysql_real_escape_string($_SESSION['profile']['email'])."'"; + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); echo $row['email']."
\n"; account_email_delete($row['id']); $delcount++; @@ -326,10 +326,10 @@ function buildSubjectFromSession() { if(is_array($_SESSION['_config']['addid'])) foreach($_SESSION['_config']['addid'] as $id) { - $res = mysqli_query($_SESSION['mconn'],"select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'"); - if(mysqli_num_rows($res) > 0) + $res = mysql_query("select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'"); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if(!$emails) $defaultemail = $row['email']; $emails .= "$count.emailAddress = ".$row['email']."\n"; @@ -345,7 +345,7 @@ function buildSubjectFromSession() { showfooter(); exit; } - $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); + $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); if($_SESSION['_config']['SSO'] == 1) $emails .= "$count.emailAddress = ".$user['uniqueID']."\n"; @@ -389,13 +389,13 @@ function buildSubjectFromSession() { `codesign`='".intval($_SESSION['_config']['codesign'])."', `disablelogin`='".($_SESSION['_config']['disablelogin']?1:0)."', `rootcert`='".intval($_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; + mysql_query($query); + $emailid = mysql_insert_id(); if(is_array($addys)) foreach($addys as $addy) - mysqli_query($_SESSION['mconn'],"insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); + mysql_query("insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); $CSRname=generatecertpath("csr","client",$emailid); $fp = fopen($CSRname, "w"); fputs($fp, $emails); @@ -411,7 +411,7 @@ function buildSubjectFromSession() { showfooter(); exit; } - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `csr_name`='$CSRname' where `id`='".intval($emailid)."'"); + mysql_query("update `emailcerts` set `csr_name`='$CSRname' where `id`='".intval($emailid)."'"); } else if($_REQUEST['keytype'] == "MS" || $_REQUEST['keytype'] == "VI") { if($csr == "") $csr = "-----BEGIN CERTIFICATE REQUEST-----\n".clean_csr($_REQUEST['CSR'])."\n-----END CERTIFICATE REQUEST-----\n"; @@ -434,7 +434,7 @@ function buildSubjectFromSession() { $defaultemail = ""; $csrsubject=""; - $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); + $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); if(strlen($user['mname']) == 1) $user['mname'] .= '.'; if($_SESSION['_config']['incname'] <= 0 || $_SESSION['_config']['incname'] > 4) @@ -450,10 +450,10 @@ function buildSubjectFromSession() { if(is_array($_SESSION['_config']['addid'])) foreach($_SESSION['_config']['addid'] as $id) { - $res = mysqli_query($_SESSION['mconn'],"select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'"); - if(mysqli_num_rows($res) > 0) + $res = mysql_query("select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'"); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($defaultemail == "") $defaultemail = $row['email']; $csrsubject .= "/emailAddress=".$row['email']; @@ -490,27 +490,27 @@ function buildSubjectFromSession() { `keytype`='".sanitizeHTML($_REQUEST['keytype'])."', `memid`='".intval($_SESSION['profile']['id'])."', `created`=FROM_UNIXTIME(UNIX_TIMESTAMP()), - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."', + `subject`='".mysql_real_escape_string($csrsubject)."', `codesign`='".intval($_SESSION['_config']['codesign'])."', `disablelogin`='".($_SESSION['_config']['disablelogin']?1:0)."', `rootcert`='".intval($_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; + mysql_query($query); + $emailid = mysql_insert_id(); if(is_array($addys)) foreach($addys as $addy) - mysqli_query($_SESSION['mconn'],"insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='".mysqli_real_escape_string($_SESSION['mconn'], $addy)."'"); + mysql_query("insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='".mysql_real_escape_string($addy)."'"); $CSRname=generatecertpath("csr","client",$emailid); $fp = fopen($CSRname, "w"); fputs($fp, $csr); fclose($fp); - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); + mysql_query("update `emailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); } waitForResult("emailcerts", $emailid, 4); $query = "select * from `emailcerts` where `id`='$emailid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { $id = 4; showheader(_("My CAcert.org Account!")); @@ -547,12 +547,12 @@ function buildSubjectFromSession() { } $newdom = trim(escapeshellarg($newdomain)); - $newdomain = mysqli_real_escape_string($_SESSION['mconn'], trim($newdomain)); + $newdomain = mysql_real_escape_string(trim($newdomain)); - $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain`='$newdomain'"); + $res1 = mysql_query("select * from `orgdomains` where `domain`='$newdomain'"); $query = "select * from `domains` where `domain`='$newdomain' and `deleted`=0"; - $res2 = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res1) > 0 || mysqli_num_rows($res2)) + $res2 = mysql_query($query); + if(mysql_num_rows($res1) > 0 || mysql_num_rows($res2)) { $oldid=0; $id = 7; @@ -579,7 +579,7 @@ function buildSubjectFromSession() { $bits = explode(":", $line, 2); $line = trim($bits[1]); if(!in_array($line, $addy) && $line != "") - $addy[] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($line))); + $addy[] = trim(mysql_real_escape_string(stripslashes($line))); } } else { if(is_array($adds)) @@ -597,7 +597,7 @@ function buildSubjectFromSession() { $line = $bit; } if(!in_array($line, $addy) && $line != "") - $addy[] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($line))); + $addy[] = trim(mysql_real_escape_string(stripslashes($line))); } } @@ -606,7 +606,7 @@ function buildSubjectFromSession() { if(!in_array($sub, $addy)) $addy[] = $sub; $_SESSION['_config']['addy'] = $addy; - $_SESSION['_config']['domain'] = mysqli_real_escape_string($_SESSION['mconn'], $newdomain); + $_SESSION['_config']['domain'] = mysql_real_escape_string($newdomain); } if($process != "" && $oldid == 8) @@ -615,7 +615,7 @@ function buildSubjectFromSession() { $oldid=0; $id = 8; - $authaddy = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['authaddy']))); + $authaddy = trim(mysql_real_escape_string(stripslashes($_REQUEST['authaddy']))); if($authaddy == "" || !is_array($_SESSION['_config']['addy'])) { @@ -633,9 +633,9 @@ function buildSubjectFromSession() { exit; } - $query = "select * from `domains` where `domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['domain'])."' and `deleted`=0"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) > 0) + $query = "select * from `domains` where `domain`='".mysql_real_escape_string($_SESSION['_config']['domain'])."' and `deleted`=0"; + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { showheader(_("My CAcert.org Account!")); printf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($_SESSION['_config']['domain'])); @@ -659,10 +659,10 @@ function buildSubjectFromSession() { } $hash = make_hash(); - $query = "insert into `domains` set `domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['domain'])."', + $query = "insert into `domains` set `domain`='".mysql_real_escape_string($_SESSION['_config']['domain'])."', `memid`='".intval($_SESSION['profile']['id'])."',`created`=NOW(),`hash`='$hash'"; - mysqli_query($_SESSION['mconn'],$query); - $domainid = mysqli_insert_id($_SESSION['mconn']); + mysql_query($query); + $domainid = mysql_insert_id(); $body = sprintf(_("Below is the link you need to open to verify your domain '%s'. Once your address is verified you will be able to start issuing certificates to your heart's content!"),$_SESSION['_config']['domain'])."\n\n"; $body .= "http://".$_SESSION['_config']['normalhostname']."/verify.php?type=domain&domainid=$domainid&hash=$hash\n\n"; @@ -689,10 +689,10 @@ function buildSubjectFromSession() { { $id = intval($id); $query = "select * from `domains` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) > 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); echo $row['domain']."
\n"; account_domain_delete($row['id']); } @@ -810,20 +810,20 @@ function buildSubjectFromSession() { if(array_key_exists('0',$_SESSION['_config']['rowid']) && $_SESSION['_config']['rowid']['0'] > 0) { $query = "insert into `domaincerts` set - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rows']['0'])."', - `domid`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rowid']['0'])."', - `created`=NOW(),`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $subject)."', - `rootcert`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; + `CN`='".mysql_real_escape_string($_SESSION['_config']['rows']['0'])."', + `domid`='".mysql_real_escape_string($_SESSION['_config']['rowid']['0'])."', + `created`=NOW(),`subject`='".mysql_real_escape_string($subject)."', + `rootcert`='".mysql_real_escape_string($_SESSION['_config']['rootcert'])."', + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; } elseif(array_key_exists('0',$_SESSION['_config']['altid']) && $_SESSION['_config']['altid']['0'] > 0) { $query = "insert into `domaincerts` set - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altrows']['0'])."', - `domid`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altid']['0'])."', - `created`=NOW(),`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $subject)."', - `rootcert`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; + `CN`='".mysql_real_escape_string($_SESSION['_config']['altrows']['0'])."', + `domid`='".mysql_real_escape_string($_SESSION['_config']['altid']['0'])."', + `created`=NOW(),`subject`='".mysql_real_escape_string($subject)."', + `rootcert`='".mysql_real_escape_string($_SESSION['_config']['rootcert'])."', + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; } else { showheader(_("My CAcert.org Account!")); echo _("Domain not verified."); @@ -831,24 +831,24 @@ function buildSubjectFromSession() { exit; } - mysqli_query($_SESSION['mconn'],$query); - $CSRid = mysqli_insert_id($_SESSION['mconn']); + mysql_query($query); + $CSRid = mysql_insert_id(); if(is_array($_SESSION['_config']['rowid'])) foreach($_SESSION['_config']['rowid'] as $dom) - mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='$dom'"); + mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='$dom'"); if(is_array($_SESSION['_config']['altid'])) foreach($_SESSION['_config']['altid'] as $dom) - mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='$dom'"); + mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='$dom'"); $CSRname=generatecertpath("csr","server",$CSRid); rename($_SESSION['_config']['tmpfname'], $CSRname); chmod($CSRname,0644); - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'"); + mysql_query("update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'"); waitForResult("domaincerts", $CSRid, 11); $query = "select * from `domaincerts` where `id`='$CSRid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { $id = 11; showheader(_("My CAcert.org Account!")); @@ -878,14 +878,14 @@ function buildSubjectFromSession() { where `domaincerts`.`id`='$id' and `domaincerts`.`domid`=`domains`.`id` and `domains`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if (($weakKey = checkWeakKeyX509(file_get_contents( $row['crt_name']))) !== "") @@ -894,20 +894,20 @@ function buildSubjectFromSession() { continue; } - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `renewed`='1' where `id`='$id'"); + mysql_query("update `domaincerts` set `renewed`='1' where `id`='$id'"); $query = "insert into `domaincerts` set `domid`='".intval($row['domid'])."', - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."', - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."',". + `CN`='".mysql_real_escape_string($row['CN'])."', + `subject`='".mysql_real_escape_string($row['subject'])."',". //`csr_name`='".$row['csr_name']."', // RACE CONDITION - "`created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."', + "`created`='".mysql_real_escape_string($row['created'])."', `modified`=NOW(), `rootcert`='".intval($row['rootcert'])."', `type`='".intval($row['type'])."', - `pkhash`='".mysqli_real_escape_string($_SESSION['mconn'], $row['pkhash'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $newid = mysqli_insert_id($_SESSION['mconn']); + `pkhash`='".mysql_real_escape_string($row['pkhash'])."', + `description`='".mysql_real_escape_string($row['description'])."'"; + mysql_query($query); + $newid = mysql_insert_id(); $newfile=generatecertpath("csr","server",$newid); copy($row['csr_name'], $newfile); $newfile_esc = escapeshellarg($newfile); @@ -929,18 +929,18 @@ function buildSubjectFromSession() { } $subject = buildSubjectFromSession(); - $subject = mysqli_real_escape_string($_SESSION['mconn'], $subject); - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `subject`='$subject',`csr_name`='$newfile' where `id`='$newid'"); + $subject = mysql_real_escape_string($subject); + mysql_query("update `domaincerts` set `subject`='$subject',`csr_name`='$newfile' where `id`='$newid'"); echo _("Renewing").": ".sanitizeHTML($_SESSION['_config']['0.CN'])."
\n"; waitForResult("domaincerts", $newid,$oldid,0); $query = "select * from `domaincerts` where `id`='$newid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", ""); } else { - $drow = mysqli_fetch_assoc($res); + $drow = mysql_fetch_assoc($res); $crt_name = escapeshellarg($drow['crt_name']); $cert = shell_exec("/usr/bin/openssl x509 -in $crt_name"); echo "
\n$cert\n
\n"; @@ -971,19 +971,19 @@ function buildSubjectFromSession() { where `domaincerts`.`id`='$id' and `domaincerts`.`domid`=`domains`.`id` and `domains`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); + mysql_query("update `domaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); printf(_("Certificate for '%s' with the serial no '%s' has been revoked.").'
', htmlspecialchars($row['CN']), htmlspecialchars($row['serial'])); } @@ -1006,19 +1006,19 @@ function buildSubjectFromSession() { where `domaincerts`.`id`='$id' and `domaincerts`.`domid`=`domains`.`id` and `domains`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['expired'] > 0) { printf(_("Couldn't remove the request for `%s`, request had already been processed.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"delete from `domaincerts` where `id`='$id'"); + mysql_query("delete from `domaincerts` where `id`='$id'"); @unlink($row['csr_name']); @unlink($row['crt_name']); printf(_("Removed a pending request for '%s'")."
\n", $row['CN']); @@ -1036,8 +1036,8 @@ function buildSubjectFromSession() { if(substr($id,0,14)=="check_comment_") { $cid = intval(substr($id,14)); - $comment=trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comment_'.$cid]))); - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `description`='$comment' where `id`='$cid'"); + $comment=trim(mysql_real_escape_string(stripslashes($_REQUEST['comment_'.$cid]))); + mysql_query("update `domaincerts` set `description`='$comment' where `id`='$cid'"); } } echo(_("Certificate settings have been changed.")."
\n"); @@ -1057,14 +1057,14 @@ function buildSubjectFromSession() { $id = intval($id); $query = "select *,UNIX_TIMESTAMP(`revoked`) as `revoke` from `emailcerts` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if (($weakKey = checkWeakKeyX509(file_get_contents( $row['crt_name']))) !== "") @@ -1073,34 +1073,34 @@ function buildSubjectFromSession() { continue; } - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `renewed`='1' where `id`='$id'"); + mysql_query("update `emailcerts` set `renewed`='1' where `id`='$id'"); $query = "insert into emailcerts set `memid`='".intval($row['memid'])."', - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."', - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."', - `keytype`='".mysqli_real_escape_string($_SESSION['mconn'], $row['keytype'])."', - `csr_name`='".mysqli_real_escape_string($_SESSION['mconn'], $row['csr_name'])."', - `created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."', + `CN`='".mysql_real_escape_string($row['CN'])."', + `subject`='".mysql_real_escape_string($row['subject'])."', + `keytype`='".mysql_real_escape_string($row['keytype'])."', + `csr_name`='".mysql_real_escape_string($row['csr_name'])."', + `created`='".mysql_real_escape_string($row['created'])."', `modified`=NOW(), `disablelogin`='".intval($row['disablelogin'])."', `codesign`='".intval($row['codesign'])."', `rootcert`='".intval($row['rootcert'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $newid = mysqli_insert_id($_SESSION['mconn']); + `description`='".mysql_real_escape_string($row['description'])."'"; + mysql_query($query); + $newid = mysql_insert_id(); $newfile=generatecertpath("csr","client",$newid); copy($row['csr_name'], $newfile); - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `csr_name`='$newfile' where `id`='$newid'"); - $res = mysqli_query($_SESSION['mconn'],"select * from `emaillink` where `emailcertsid`='".$row['id']."'"); - while($r2 = mysqli_fetch_assoc($res)) + mysql_query("update `emailcerts` set `csr_name`='$newfile' where `id`='$newid'"); + $res = mysql_query("select * from `emaillink` where `emailcertsid`='".$row['id']."'"); + while($r2 = mysql_fetch_assoc($res)) { - mysqli_query($_SESSION['mconn'],"insert into `emaillink` set `emailid`='".$r2['emailid']."', + mysql_query("insert into `emaillink` set `emailid`='".$r2['emailid']."', `emailcertsid`='$newid'"); } waitForResult("emailcerts", $newid,$oldid,0); $query = "select * from `emailcerts` where `id`='$newid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", ""); } else { @@ -1131,19 +1131,19 @@ function buildSubjectFromSession() { $id = intval($id); $query = "select *,UNIX_TIMESTAMP(`revoked`) as `revoke` from `emailcerts` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); + mysql_query("update `emailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); printf(_("Certificate for '%s' with the serial no '%s' has been revoked.").'
', htmlspecialchars($row['CN']), htmlspecialchars($row['serial'])); } @@ -1163,19 +1163,19 @@ function buildSubjectFromSession() { $id = intval($id); $query = "select *,UNIX_TIMESTAMP(`expire`) as `expired` from `emailcerts` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['expired'] > 0) { printf(_("Couldn't remove the request for `%s`, request had already been processed.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"delete from `emailcerts` where `id`='$id'"); + mysql_query("delete from `emailcerts` where `id`='$id'"); @unlink($row['csr_name']); @unlink($row['crt_name']); printf(_("Removed a pending request for '%s'")."
\n", $row['CN']); @@ -1194,14 +1194,14 @@ function buildSubjectFromSession() { { $cid = intval(substr($id,5)); $dis=(array_key_exists('disablelogin_'.$cid,$_REQUEST) && $_REQUEST['disablelogin_'.$cid]=="1")?"0":"1"; - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `disablelogin`='$dis' where `id`='$cid' and `memid`='".intval($_SESSION['profile']['id'])."'"); + mysql_query("update `emailcerts` set `disablelogin`='$dis' where `id`='$cid' and `memid`='".intval($_SESSION['profile']['id'])."'"); } if(substr($id,0,14)=="check_comment_") { $cid = intval(substr($id,14)); if(!empty($_REQUEST['check_comment_'.$cid])) { - $comment=trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comment_'.$cid]))); - mysqli_query($_SESSION['mconn'],"update `emailcerts` set `description`='$comment' where `id`='$cid' and `memid`='".intval($_SESSION['profile']['id'])."'"); + $comment=trim(mysql_real_escape_string(stripslashes($_REQUEST['comment_'.$cid]))); + mysql_query("update `emailcerts` set `description`='$comment' where `id`='$cid' and `memid`='".intval($_SESSION['profile']['id'])."'"); } } } @@ -1215,16 +1215,16 @@ function buildSubjectFromSession() { csrf_check("perschange"); $_SESSION['_config']['user'] = $_SESSION['profile']; - $_SESSION['_config']['user']['Q1'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['Q1'])))); - $_SESSION['_config']['user']['Q2'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['Q2'])))); - $_SESSION['_config']['user']['Q3'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['Q3'])))); - $_SESSION['_config']['user']['Q4'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['Q4'])))); - $_SESSION['_config']['user']['Q5'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['Q5'])))); - $_SESSION['_config']['user']['A1'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['A1'])))); - $_SESSION['_config']['user']['A2'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['A2'])))); - $_SESSION['_config']['user']['A3'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['A3'])))); - $_SESSION['_config']['user']['A4'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['A4'])))); - $_SESSION['_config']['user']['A5'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['A5'])))); + $_SESSION['_config']['user']['Q1'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['Q1'])))); + $_SESSION['_config']['user']['Q2'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['Q2'])))); + $_SESSION['_config']['user']['Q3'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['Q3'])))); + $_SESSION['_config']['user']['Q4'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['Q4'])))); + $_SESSION['_config']['user']['Q5'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['Q5'])))); + $_SESSION['_config']['user']['A1'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['A1'])))); + $_SESSION['_config']['user']['A2'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['A2'])))); + $_SESSION['_config']['user']['A3'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['A3'])))); + $_SESSION['_config']['user']['A4'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['A4'])))); + $_SESSION['_config']['user']['A5'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['A5'])))); if($_SESSION['_config']['user']['Q1'] == $_SESSION['_config']['user']['Q2'] || $_SESSION['_config']['user']['Q1'] == $_SESSION['_config']['user']['Q3'] || @@ -1276,16 +1276,16 @@ function buildSubjectFromSession() { if($oldid == 13 && $process != "") { $ddquery = "select sum(`points`) as `total` from `notary` where `to`='".intval($_SESSION['profile']['id'])."' and `deleted` = 0 group by `to`"; - $ddres = mysqli_query($_SESSION['mconn'],$ddquery); - $ddrow = mysqli_fetch_assoc($ddres); + $ddres = mysql_query($ddquery); + $ddrow = mysql_fetch_assoc($ddres); $_SESSION['profile']['points'] = $ddrow['total']; if($_SESSION['profile']['points'] == 0) { - $_SESSION['_config']['user']['fname'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['fname'])))); - $_SESSION['_config']['user']['mname'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['mname'])))); - $_SESSION['_config']['user']['lname'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['lname'])))); - $_SESSION['_config']['user']['suffix'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes(strip_tags($_REQUEST['suffix'])))); + $_SESSION['_config']['user']['fname'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['fname'])))); + $_SESSION['_config']['user']['mname'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['mname'])))); + $_SESSION['_config']['user']['lname'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['lname'])))); + $_SESSION['_config']['user']['suffix'] = trim(mysql_real_escape_string(stripslashes(strip_tags($_REQUEST['suffix'])))); $_SESSION['_config']['user']['day'] = intval($_REQUEST['day']); $_SESSION['_config']['user']['month'] = intval($_REQUEST['month']); $_SESSION['_config']['user']['year'] = intval($_REQUEST['year']); @@ -1316,7 +1316,7 @@ function buildSubjectFromSession() { `suffix`='".$_SESSION['_config']['user']['suffix']."', `dob`='".$_SESSION['_config']['user']['year']."-".$_SESSION['_config']['user']['month']."-".$_SESSION['_config']['user']['day']."' where `id`='".intval($_SESSION['profile']['id'])."'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); } if ($showdetails!="") { $query = "update `users` set `Q1`='".$_SESSION['_config']['user']['Q1']."', @@ -1330,16 +1330,16 @@ function buildSubjectFromSession() { `A4`='".$_SESSION['_config']['user']['A4']."', `A5`='".$_SESSION['_config']['user']['A5']."' where `id`='".intval($_SESSION['profile']['id'])."'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); } $_SESSION['_config']['user']['set'] = 0; - $_SESSION['profile'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); + $_SESSION['profile'] = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'")); $_SESSION['profile']['loggedin'] = 1; $ddquery = "select sum(`points`) as `total` from `notary` where `to`='".intval($_SESSION['profile']['id'])."' and `deleted` = 0 group by `to`"; - $ddres = mysqli_query($_SESSION['mconn'],$ddquery); - $ddrow = mysqli_fetch_assoc($ddres); + $ddres = mysql_query($ddquery); + $ddrow = mysql_fetch_assoc($ddres); $_SESSION['profile']['points'] = $ddrow['total']; @@ -1352,9 +1352,9 @@ function buildSubjectFromSession() { if($oldid == 14 && $process != "") { - $_SESSION['_config']['user']['oldpass'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['oldpassword']))); - $_SESSION['_config']['user']['pword1'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['pword1']))); - $_SESSION['_config']['user']['pword2'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['pword2']))); + $_SESSION['_config']['user']['oldpass'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['oldpassword']))); + $_SESSION['_config']['user']['pword1'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['pword1']))); + $_SESSION['_config']['user']['pword2'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['pword2']))); $id = 14; csrf_check("pwchange"); @@ -1371,10 +1371,10 @@ function buildSubjectFromSession() { if($_SESSION['_config']['hostname'] != $_SESSION['_config']['securehostname']) { - $match = mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."' and + $match = mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."' and (`password`=old_password('".$_SESSION['_config']['user']['oldpass']."') or `password`=sha1('".$_SESSION['_config']['user']['oldpass']."'))"); - $rc = mysqli_num_rows($match); + $rc = mysql_num_rows($match); } else { $rc = 1; } @@ -1392,7 +1392,7 @@ function buildSubjectFromSession() { _("Failure: Pass Phrase not Changed"), '', "\n"; echo _("You failed to correctly enter your current Pass Phrase."); } else { - mysqli_query($_SESSION['mconn'],"update `users` set `password`=sha1('".$_SESSION['_config']['user']['pword1']."') + mysql_query("update `users` set `password`=sha1('".$_SESSION['_config']['user']['pword1']."') where `id`='".intval($_SESSION['profile']['id'])."'"); echo '

', _("Pass Phrase Changed Successfully"), '

', "\n"; echo _("Your Pass Phrase has been updated and your primary email account has been notified of the change."); @@ -1417,7 +1417,7 @@ function buildSubjectFromSession() { foreach($_REQUEST['emails'] as $val) { - $val = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($val))); + $val = mysql_real_escape_string(stripslashes(trim($val))); $bits = explode("@", $val); $count = count($bits); if($count != 2) @@ -1434,7 +1434,7 @@ function buildSubjectFromSession() { if($val != "") $_SESSION['_config']['emails'][] = $val; } - $_SESSION['_config']['name'] = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['name']))); + $_SESSION['_config']['name'] = mysql_real_escape_string(stripslashes(trim($_REQUEST['name']))); $_SESSION['_config']['OU'] = stripslashes(trim($_REQUEST['OU'])); $_SESSION['_config']['description']= trim(stripslashes($_REQUEST['description'])); @@ -1504,7 +1504,7 @@ function buildSubjectFromSession() { if($_SESSION['_config']['name'] != "") $emails .= "commonName = ".$_SESSION['_config']['name']."\n"; if($_SESSION['_config']['OU']) - $emails .= "organizationalUnitName = ".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['OU'])."\n"; + $emails .= "organizationalUnitName = ".mysql_real_escape_string($_SESSION['_config']['OU'])."\n"; if($org['O']) $emails .= "organizationName = ".$org['O']."\n"; if($org['L']) @@ -1529,19 +1529,19 @@ function buildSubjectFromSession() { $query = "insert into `orgemailcerts` set `CN`='$defaultemail', - `ou`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['OU'])."', + `ou`='".mysql_real_escape_string($_SESSION['_config']['OU'])."', `keytype`='NS', `orgid`='".intval($org['orgid'])."', `created`=FROM_UNIXTIME(UNIX_TIMESTAMP()), `codesign`='".intval($_SESSION['_config']['codesign'])."', `rootcert`='".intval($_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; + mysql_query($query); + $emailid = mysql_insert_id(); foreach($_SESSION['_config']['domids'] as $addy) - mysqli_query($_SESSION['mconn'],"insert into `domemaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); + mysql_query("insert into `domemaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); $CSRname=generatecertpath("csr","orgclient",$emailid); $fp = fopen($CSRname, "w"); @@ -1558,7 +1558,7 @@ function buildSubjectFromSession() { showfooter(); exit; } - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); + mysql_query("update `orgemailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); } else if($_REQUEST['keytype'] == "MS" || $_REQUEST['keytype']=="VI") { $csr = clean_csr($_REQUEST['CSR']); if(strpos($csr,"---BEGIN") === FALSE) @@ -1629,31 +1629,31 @@ function buildSubjectFromSession() { $query = "insert into `orgemailcerts` set `CN`='$defaultemail', - `ou`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['OU'])."', + `ou`='".mysql_real_escape_string($_SESSION['_config']['OU'])."', `keytype`='" . sanitizeHTML($_REQUEST['keytype']) . "', `orgid`='".intval($org['orgid'])."', `created`=FROM_UNIXTIME(UNIX_TIMESTAMP()), - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."', + `subject`='".mysql_real_escape_string($csrsubject)."', `codesign`='".intval($_SESSION['_config']['codesign'])."', `rootcert`='".intval($_SESSION['_config']['rootcert'])."', - `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."', + `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'"; + mysql_query($query); + $emailid = mysql_insert_id(); foreach($_SESSION['_config']['domids'] as $addy) - mysqli_query($_SESSION['mconn'],"insert into `domemaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); + mysql_query("insert into `domemaillink` set `emailcertsid`='$emailid', `emailid`='$addy'"); $CSRname=generatecertpath("csr","orgclient",$emailid); $fp = fopen($CSRname, "w"); fputs($fp, $csr); fclose($fp); - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); + mysql_query("update `orgemailcerts` set `csr_name`='$CSRname' where `id`='$emailid'"); } waitForResult("orgemailcerts", $emailid,$oldid); $query = "select * from `orgemailcerts` where `id`='$emailid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { showheader(_("My CAcert.org Account!")); printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", ""); @@ -1681,14 +1681,14 @@ function buildSubjectFromSession() { $query = "select *,UNIX_TIMESTAMP(`revoked`) as `revoke` from `orgemailcerts`, `org` where `orgemailcerts`.`id`='$id' and `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orgemailcerts`.`orgid`"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if (($weakKey = checkWeakKeyX509(file_get_contents( $row['crt_name']))) !== "") @@ -1697,7 +1697,7 @@ function buildSubjectFromSession() { continue; } - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `renewed`='1' where `id`='$id'"); + mysql_query("update `orgemailcerts` set `renewed`='1' where `id`='$id'"); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); @@ -1705,25 +1705,25 @@ function buildSubjectFromSession() { } $query = "insert into `orgemailcerts` set `orgid`='".intval($row['orgid'])."', - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."', - `ou`='".mysqli_real_escape_string($_SESSION['mconn'], $row['ou'])."', - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."', - `keytype`='".mysqli_real_escape_string($_SESSION['mconn'], $row['keytype'])."', - `csr_name`='".mysqli_real_escape_string($_SESSION['mconn'], $row['csr_name'])."', - `created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."', + `CN`='".mysql_real_escape_string($row['CN'])."', + `ou`='".mysql_real_escape_string($row['ou'])."', + `subject`='".mysql_real_escape_string($row['subject'])."', + `keytype`='".mysql_real_escape_string($row['keytype'])."', + `csr_name`='".mysql_real_escape_string($row['csr_name'])."', + `created`='".mysql_real_escape_string($row['created'])."', `modified`=NOW(), `codesign`='".intval($row['codesign'])."', `rootcert`='".intval($row['rootcert'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $newid = mysqli_insert_id($_SESSION['mconn']); + `description`='".mysql_real_escape_string($row['description'])."'"; + mysql_query($query); + $newid = mysql_insert_id(); $newfile=generatecertpath("csr","orgclient",$newid); copy($row['csr_name'], $newfile); - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `csr_name`='$newfile' where `id`='$newid'"); + mysql_query("update `orgemailcerts` set `csr_name`='$newfile' where `id`='$newid'"); waitForResult("orgemailcerts", $newid,$oldid,0); $query = "select * from `orgemailcerts` where `id`='$newid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) > 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { printf(_("Certificate for '%s' has been renewed."), $row['CN']); echo "". @@ -1754,19 +1754,19 @@ function buildSubjectFromSession() { $query = "select *,UNIX_TIMESTAMP(`revoked`) as `revoke` from `orgemailcerts`, `org` where `orgemailcerts`.`id`='".intval($id)."' and `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orgemailcerts`.`orgid`"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); + mysql_query("update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); printf(_("Certificate for '%s' with the serial no '%s' has been revoked.").'
', htmlspecialchars($row['CN']), htmlspecialchars($row['serial'])); } @@ -1787,19 +1787,19 @@ function buildSubjectFromSession() { $query = "select *,UNIX_TIMESTAMP(`expire`) as `expired` from `orgemailcerts`, `org` where `orgemailcerts`.`id`='".intval($id)."' and `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orgemailcerts`.`orgid`"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['expired'] > 0) { printf(_("Couldn't remove the request for `%s`, request had already been processed.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"delete from `orgemailcerts` where `id`='$id'"); + mysql_query("delete from `orgemailcerts` where `id`='$id'"); @unlink($row['csr_name']); @unlink($row['crt_name']); printf(_("Removed a pending request for '%s'")."
\n", $row['CN']); @@ -1817,8 +1817,8 @@ function buildSubjectFromSession() { if(substr($id,0,14)=="check_comment_") { $cid = intval(substr($id,14)); - $comment=trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comment_'.$cid]))); - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `description`='$comment' where `id`='$cid'"); + $comment=trim(mysql_real_escape_string(stripslashes($_REQUEST['comment_'.$cid]))); + mysql_query("update `orgemailcerts` set `description`='$comment' where `id`='$cid'"); } } echo(_("Certificate settings have been changed.")."
\n"); @@ -1879,14 +1879,14 @@ function buildSubjectFromSession() { `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orginfo`.`id` and `org`.`orgid`=`orgdomains`.`orgid` and - `orgdomains`.`domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['0.CN'])."'"; - $_SESSION['_config']['CNorg'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + `orgdomains`.`domain`='".mysql_real_escape_string($_SESSION['_config']['0.CN'])."'"; + $_SESSION['_config']['CNorg'] = mysql_fetch_assoc(mysql_query($query)); $query = "select * from `orginfo`,`org`,`orgdomains` where `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orginfo`.`id` and `org`.`orgid`=`orgdomains`.`orgid` and - `orgdomains`.`domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['0.subjectAltName'])."'"; - $_SESSION['_config']['SANorg'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + `orgdomains`.`domain`='".mysql_real_escape_string($_SESSION['_config']['0.subjectAltName'])."'"; + $_SESSION['_config']['SANorg'] = mysql_fetch_assoc(mysql_query($query)); //echo "
"; print_r($_SESSION['_config']); die;
 
 		if($_SESSION['_config']['0.CN'] == "" && $_SESSION['_config']['0.subjectAltName'] == "")
@@ -1946,7 +1946,7 @@ function buildSubjectFromSession() {
 					`orginfo`.`id`=`org`.`orgid` and
 					`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
 		}
-		$org = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+		$org = mysql_fetch_assoc(mysql_query($query));
 		$csrsubject = "";
 
 		if($_SESSION['_config']['OU'])
@@ -1972,42 +1972,42 @@ function buildSubjectFromSession() {
 		if($_SESSION['_config']['rowid']['0'] > 0)
 		{
 			$query = "insert into `orgdomaincerts` set
-					`CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rows']['0'])."',
+					`CN`='".mysql_real_escape_string($_SESSION['_config']['rows']['0'])."',
 					`orgid`='".intval($org['id'])."',
 					`created`=NOW(),
-					`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."',
+					`subject`='".mysql_real_escape_string($csrsubject)."',
 					`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
-					`md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
+					`md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
 					`type`='".$type."',
-					`description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+					`description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
 		} else {
 			$query = "insert into `orgdomaincerts` set
-					`CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altrows']['0'])."',
+					`CN`='".mysql_real_escape_string($_SESSION['_config']['altrows']['0'])."',
 					`orgid`='".intval($org['id'])."',
 					`created`=NOW(),
-					`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."',
+					`subject`='".mysql_real_escape_string($csrsubject)."',
 					`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
-					`md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
+					`md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
 					`type`='".$type."',
-					`description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+					`description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
 		}
-		mysqli_query($_SESSION['mconn'],$query);
-		$CSRid = mysqli_insert_id($_SESSION['mconn']);
+		mysql_query($query);
+		$CSRid = mysql_insert_id();
 
 		$CSRname=generatecertpath("csr","orgserver",$CSRid);
 		rename($_SESSION['_config']['tmpfname'], $CSRname);
 		chmod($CSRname,0644);
-		mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
+		mysql_query("update `orgdomaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
 		if(is_array($_SESSION['_config']['rowid']))
 			foreach($_SESSION['_config']['rowid'] as $id)
-				mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
+				mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
 		if(is_array($_SESSION['_config']['altid']))
 			foreach($_SESSION['_config']['altid'] as $id)
-				mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
+				mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
 		waitForResult("orgdomaincerts", $CSRid,$oldid);
 		$query = "select * from `orgdomaincerts` where `id`='$CSRid' and `crt_name` != ''";
-		$res = mysqli_query($_SESSION['mconn'],$query);
-		if(mysqli_num_rows($res) <= 0)
+		$res = mysql_query($query);
+		if(mysql_num_rows($res) <= 0)
 		{
 			showheader(_("My CAcert.org Account!"));
 			printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions.")." CSRid: $CSRid", "", "");
@@ -2035,14 +2035,14 @@ function buildSubjectFromSession() {
 						where `orgdomaincerts`.`id`='$id' and
 						`orgdomaincerts`.`orgid`=`org`.`orgid` and
 						`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
-				$res = mysqli_query($_SESSION['mconn'],$query);
-				if(mysqli_num_rows($res) <= 0)
+				$res = mysql_query($query);
+				if(mysql_num_rows($res) <= 0)
 				{
 					printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if (($weakKey = checkWeakKeyX509(file_get_contents( $row['crt_name']))) !== "") @@ -2051,7 +2051,7 @@ function buildSubjectFromSession() { continue; } - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `renewed`='1' where `id`='$id'"); + mysql_query("update `orgdomaincerts` set `renewed`='1' where `id`='$id'"); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); @@ -2059,32 +2059,32 @@ function buildSubjectFromSession() { } $query = "insert into `orgdomaincerts` set `orgid`='".intval($row['orgid'])."', - `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."', - `csr_name`='".mysqli_real_escape_string($_SESSION['mconn'], $row['csr_name'])."', - `created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."', + `CN`='".mysql_real_escape_string($row['CN'])."', + `csr_name`='".mysql_real_escape_string($row['csr_name'])."', + `created`='".mysql_real_escape_string($row['created'])."', `modified`=NOW(), - `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."', + `subject`='".mysql_real_escape_string($row['subject'])."', `type`='".intval($row['type'])."', `rootcert`='".intval($row['rootcert'])."', - `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'"; - mysqli_query($_SESSION['mconn'],$query); - $newid = mysqli_insert_id($_SESSION['mconn']); + `description`='".mysql_real_escape_string($row['description'])."'"; + mysql_query($query); + $newid = mysql_insert_id(); //echo "NewID: $newid
\n"; $newfile=generatecertpath("csr","orgserver",$newid); copy($row['csr_name'], $newfile); - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `csr_name`='$newfile' where `id`='$newid'"); + mysql_query("update `orgdomaincerts` set `csr_name`='$newfile' where `id`='$newid'"); echo _("Renewing").": ".$row['CN']."
\n"; - $res = mysqli_query($_SESSION['mconn'],"select * from `orgdomlink` where `orgcertid`='".$row['id']."'"); - while($r2 = mysqli_fetch_assoc($res)) - mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($r2['orgdomid'])."', `orgcertid`='$newid'"); + $res = mysql_query("select * from `orgdomlink` where `orgcertid`='".$row['id']."'"); + while($r2 = mysql_fetch_assoc($res)) + mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($r2['orgdomid'])."', `orgcertid`='$newid'"); waitForResult("orgdomaincerts", $newid,$oldid,0); $query = "select * from `orgdomaincerts` where `id`='$newid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions.")." newid: $newid", "", ""); } else { - $drow = mysqli_fetch_assoc($res); + $drow = mysql_fetch_assoc($res); $crtname = escapeshellarg($drow['crt_name']); $cert = shell_exec("/usr/bin/openssl x509 -in $crtname"); echo "
\n$cert\n
\n"; @@ -2114,19 +2114,19 @@ function buildSubjectFromSession() { where `orgdomaincerts`.`id`='$id' and `orgdomaincerts`.`orgid`=`org`.`orgid` and `org`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['revoke'] > 0) { printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); + mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'"); printf(_("Certificate for '%s' with the serial no '%s' has been revoked.").'
', htmlspecialchars($row['CN']), htmlspecialchars($row['serial'])); } @@ -2149,19 +2149,19 @@ function buildSubjectFromSession() { where `orgdomaincerts`.`id`='$id' and `orgdomaincerts`.`orgid`=`org`.`orgid` and `org`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id); continue; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if($row['expired'] > 0) { printf(_("Couldn't remove the request for `%s`, request had already been processed.")."
\n", $row['CN']); continue; } - mysqli_query($_SESSION['mconn'],"delete from `orgdomaincerts` where `id`='$id'"); + mysql_query("delete from `orgdomaincerts` where `id`='$id'"); @unlink($row['csr_name']); @unlink($row['crt_name']); printf(_("Removed a pending request for '%s'")."
\n", $row['CN']); @@ -2179,8 +2179,8 @@ function buildSubjectFromSession() { if(substr($id,0,14)=="check_comment_") { $cid = intval(substr($id,14)); - $comment=trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comment_'.$cid]))); - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `description`='$comment' where `id`='$cid'"); + $comment=trim(mysql_real_escape_string(stripslashes($_REQUEST['comment_'.$cid]))); + mysql_query("update `orgdomaincerts` set `description`='$comment' where `id`='$cid'"); } } echo(_("Certificate settings have been changed.")."
\n"); @@ -2219,18 +2219,18 @@ function buildSubjectFromSession() { if($oldid == 24 && $process != "") { $id = intval($oldid); - $_SESSION['_config']['O'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['O']))); - $_SESSION['_config']['contact'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['contact']))); - $_SESSION['_config']['L'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['L']))); - $_SESSION['_config']['ST'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['ST']))); - $_SESSION['_config']['C'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['C']))); - $_SESSION['_config']['comments'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comments']))); + $_SESSION['_config']['O'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['O']))); + $_SESSION['_config']['contact'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['contact']))); + $_SESSION['_config']['L'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['L']))); + $_SESSION['_config']['ST'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['ST']))); + $_SESSION['_config']['C'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['C']))); + $_SESSION['_config']['comments'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['comments']))); if($_SESSION['_config']['O'] == "" || $_SESSION['_config']['contact'] == "") { $_SESSION['_config']['errmsg'] = _("Organisation Name and Contact Email are required fields."); } else { - mysqli_query($_SESSION['mconn'],"insert into `orginfo` set `O`='".$_SESSION['_config']['O']."', + mysql_query("insert into `orginfo` set `O`='".$_SESSION['_config']['O']."', `contact`='".$_SESSION['_config']['contact']."', `L`='".$_SESSION['_config']['L']."', `ST`='".$_SESSION['_config']['ST']."', @@ -2247,18 +2247,18 @@ function buildSubjectFromSession() { { csrf_check('orgdetchange'); $id = intval($oldid); - $_SESSION['_config']['O'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['O']))); - $_SESSION['_config']['contact'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['contact']))); - $_SESSION['_config']['L'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['L']))); - $_SESSION['_config']['ST'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['ST']))); - $_SESSION['_config']['C'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['C']))); - $_SESSION['_config']['comments'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comments']))); + $_SESSION['_config']['O'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['O']))); + $_SESSION['_config']['contact'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['contact']))); + $_SESSION['_config']['L'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['L']))); + $_SESSION['_config']['ST'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['ST']))); + $_SESSION['_config']['C'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['C']))); + $_SESSION['_config']['comments'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['comments']))); if($_SESSION['_config']['O'] == "" || $_SESSION['_config']['contact'] == "") { $_SESSION['_config']['errmsg'] = _("Organisation Name and Contact Email are required fields."); } else { - mysqli_query($_SESSION['mconn'],"update `orginfo` set `O`='".$_SESSION['_config']['O']."', + mysql_query("update `orginfo` set `O`='".$_SESSION['_config']['O']."', `contact`='".$_SESSION['_config']['contact']."', `L`='".$_SESSION['_config']['L']."', `ST`='".$_SESSION['_config']['ST']."', @@ -2274,9 +2274,9 @@ function buildSubjectFromSession() { if($oldid == 28 && $process != "" && array_key_exists("domainname",$_REQUEST)) { - $domain = $_SESSION['_config']['domain'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['domainname']))); - $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain`='$domain'"); - if(mysqli_num_rows($res1) > 0) + $domain = $_SESSION['_config']['domain'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['domainname']))); + $res1 = mysql_query("select * from `orgdomains` where `domain`='$domain'"); + if(mysql_num_rows($res1) > 0) { $_SESSION['_config']['errmsg'] = sprintf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($domain)); $id = $oldid; @@ -2292,7 +2292,7 @@ function buildSubjectFromSession() { if($oldid == 28 && $process != "" && array_key_exists("orgid",$_SESSION["_config"])) { - mysqli_query($_SESSION['mconn'],"insert into `orgdomains` set `orgid`='".intval($_SESSION['_config']['orgid'])."', `domain`='$domain'"); + mysql_query("insert into `orgdomains` set `orgid`='".intval($_SESSION['_config']['orgid'])."', `domain`='$domain'"); showheader(_("My CAcert.org Account!")); printf(_("'%s' has just been successfully added to the database."), sanitizeHTML($domain)); echo "

"._("Click here")." "._("to continue."); @@ -2302,11 +2302,11 @@ function buildSubjectFromSession() { if($oldid == 29 && $process != "") { - $domain = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['domainname']))); + $domain = mysql_real_escape_string(stripslashes(trim($_REQUEST['domainname']))); - $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain` like '$domain' and `id`!='".intval($domid)."'"); - $res2 = mysqli_query($_SESSION['mconn'],"select * from `domains` where `domain` like '$domain' and `deleted`=0"); - if(mysqli_num_rows($res1) > 0 || mysqli_num_rows($res2) > 0) + $res1 = mysql_query("select * from `orgdomains` where `domain` like '$domain' and `id`!='".intval($domid)."'"); + $res2 = mysql_query("select * from `domains` where `domain` like '$domain' and `deleted`=0"); + if(mysql_num_rows($res1) > 0 || mysql_num_rows($res2) > 0) { $_SESSION['_config']['errmsg'] = sprintf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($domain)); $id = $oldid; @@ -2320,23 +2320,23 @@ function buildSubjectFromSession() { `orgdomlink`.`orgdomid`=`orgdomains`.`id` and `orgdomaincerts`.`id`=`orgdomlink`.`orgcertid` and `orgdomains`.`id`='".intval($domid)."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - while($row = mysqli_fetch_assoc($res)) - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".$row['id']."'"); + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) + mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".$row['id']."'"); $query = "select `orgemailcerts`.`id` as `id` from `orgemailcerts`, `orgemaillink`, `orgdomains` where `orgemaillink`.`domid`=`orgdomains`.`id` and `orgemailcerts`.`id`=`orgemaillink`.`emailcertsid` and `orgdomains`.`id`='".intval($domid)."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - while($row = mysqli_fetch_assoc($res)) - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) + mysql_query("update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); } if($oldid == 29 && $process != "") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `id`='".intval($domid)."'")); - mysqli_query($_SESSION['mconn'],"update `orgdomains` set `domain`='$domain' where `id`='".intval($domid)."'"); + $row = mysql_fetch_assoc(mysql_query("select * from `orgdomains` where `id`='".intval($domid)."'")); + mysql_query("update `orgdomains` set `domain`='$domain' where `id`='".intval($domid)."'"); showheader(_("My CAcert.org Account!")); printf(_("'%s' has just been successfully updated in the database."), sanitizeHTML($domain)); echo "

"._("Click here")." "._("to continue."); @@ -2346,9 +2346,9 @@ function buildSubjectFromSession() { if($oldid == 30 && $process != "") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `id`='".intval($domid)."'")); + $row = mysql_fetch_assoc(mysql_query("select * from `orgdomains` where `id`='".intval($domid)."'")); $domain = $row['domain']; - mysqli_query($_SESSION['mconn'],"delete from `orgdomains` where `id`='".intval($domid)."'"); + mysql_query("delete from `orgdomains` where `id`='".intval($domid)."'"); showheader(_("My CAcert.org Account!")); printf(_("'%s' has just been successfully deleted from the database."), sanitizeHTML($domain)); echo "

"._("Click here")." "._("to continue."); @@ -2365,36 +2365,36 @@ function buildSubjectFromSession() { if($oldid == 31 && $process != "") { $query = "select * from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'"; - $dres = mysqli_query($_SESSION['mconn'],$query); - while($drow = mysqli_fetch_assoc($dres)) + $dres = mysql_query($query); + while($drow = mysql_fetch_assoc($dres)) { $query = "select `orgdomaincerts`.`id` as `id` from `orgdomlink`, `orgdomaincerts`, `orgdomains` where `orgdomlink`.`orgdomid`=`orgdomains`.`id` and `orgdomaincerts`.`id`=`orgdomlink`.`orgcertid` and `orgdomains`.`id`='".intval($drow['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { - mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orgdomaincerts` where `orgid`='".intval($row['id'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orgdomlink` where `domid`='".intval($row['id'])."'"); + mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); + mysql_query("delete from `orgdomaincerts` where `orgid`='".intval($row['id'])."'"); + mysql_query("delete from `orgdomlink` where `domid`='".intval($row['id'])."'"); } $query = "select `orgemailcerts`.`id` as `id` from `orgemailcerts`, `orgemaillink`, `orgdomains` where `orgemaillink`.`domid`=`orgdomains`.`id` and `orgemailcerts`.`id`=`orgemaillink`.`emailcertsid` and `orgdomains`.`id`='".intval($drow['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { - mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orgemailcerts` where `id`='".intval($row['id'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orgemaillink` where `domid`='".intval($row['id'])."'"); + mysql_query("update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'"); + mysql_query("delete from `orgemailcerts` where `id`='".intval($row['id'])."'"); + mysql_query("delete from `orgemaillink` where `domid`='".intval($row['id'])."'"); } } - mysqli_query($_SESSION['mconn'],"delete from `org` where `orgid`='".intval($_SESSION['_config']['orgid'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'"); - mysqli_query($_SESSION['mconn'],"delete from `orginfo` where `id`='".intval($_SESSION['_config']['orgid'])."'"); + mysql_query("delete from `org` where `orgid`='".intval($_SESSION['_config']['orgid'])."'"); + mysql_query("delete from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'"); + mysql_query("delete from `orginfo` where `id`='".intval($_SESSION['_config']['orgid'])."'"); } if($oldid == 31) @@ -2406,7 +2406,7 @@ function buildSubjectFromSession() { if($id == 32 || $oldid == 32 || $id == 33 || $oldid == 33 || $id == 34 || $oldid == 34) { $query = "select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'"; - $_macc = mysqli_num_rows(mysqli_query($_SESSION['mconn'],$query)); + $_macc = mysql_num_rows(mysql_query($query)); if($_SESSION['profile']['orgadmin'] != 1 && $_macc <= 0) { showheader(_("My CAcert.org Account!")); @@ -2419,7 +2419,7 @@ function buildSubjectFromSession() { if($id == 35 || $oldid == 35) { $query = "select 1 from `org` where `memid`='".intval($_SESSION['profile']['id'])."'"; - $is_orguser = mysqli_num_rows(mysqli_query($_SESSION['mconn'],$query)); + $is_orguser = mysql_num_rows(mysql_query($query)); if($_SESSION['profile']['orgadmin'] != 1 && $is_orguser <= 0) { showheader(_("My CAcert.org Account!")); @@ -2433,8 +2433,8 @@ function buildSubjectFromSession() { { $orgid = intval($_SESSION['_config']['orgid']); $query = "select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { $id = 35; } @@ -2447,17 +2447,17 @@ function buildSubjectFromSession() { $masteracc = $_SESSION['_config']['masteracc'] = intval($_REQUEST['masteracc']); else $masteracc = $_SESSION['_config']['masteracc'] = 0; - $_REQUEST['email'] = $_SESSION['_config']['email'] = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['email']))); + $_REQUEST['email'] = $_SESSION['_config']['email'] = mysql_real_escape_string(stripslashes(trim($_REQUEST['email']))); $_SESSION['_config']['OU'] = stripslashes(trim($_REQUEST['OU'])); - $comments = $_SESSION['_config']['comments'] = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['comments']))); - $res = mysqli_query($_SESSION['mconn'],"select * from `users` where `email`='".$_REQUEST['email']."' and `deleted`=0"); - if(mysqli_num_rows($res) <= 0) + $comments = $_SESSION['_config']['comments'] = mysql_real_escape_string(stripslashes(trim($_REQUEST['comments']))); + $res = mysql_query("select * from `users` where `email`='".$_REQUEST['email']."' and `deleted`=0"); + if(mysql_num_rows($res) <= 0) { $id = $oldid; $oldid=0; $_SESSION['_config']['errmsg'] = sprintf(_("Wasn't able to match '%s' against any user in the system"), sanitizeHTML($_REQUEST['email'])); } else { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); if ( !is_assurer(intval($row['id'])) ) { $id = $oldid; @@ -2465,12 +2465,12 @@ function buildSubjectFromSession() { $_SESSION['_config']['errmsg'] = _("The user is not an Assurer yet"); } else { - mysqli_query($_SESSION['mconn'], + mysql_query( "insert into `org` set `memid`='".intval($row['id'])."', `orgid`='".intval($_SESSION['_config']['orgid'])."', `masteracc`='$masteracc', - `OU`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['OU'])."', + `OU`='".mysql_real_escape_string($_SESSION['_config']['OU'])."', `comments`='$comments'"); } } @@ -2479,8 +2479,8 @@ function buildSubjectFromSession() { if(($oldid == 34 || $id == 34) && $_SESSION['profile']['orgadmin'] != 1) { $orgid = intval($_SESSION['_config']['orgid']); - $res = mysqli_query($_SESSION['mconn'],"select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'"); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query("select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'"); + if(mysql_num_rows($res) <= 0) $id = 32; } @@ -2489,7 +2489,7 @@ function buildSubjectFromSession() { $orgid = intval($_SESSION['_config']['orgid']); $memid = intval($_REQUEST['memid']); $query = "delete from `org` where `orgid`='$orgid' and `memid`='$memid'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); } if($oldid == 34 || $oldid == 33) @@ -2501,7 +2501,7 @@ function buildSubjectFromSession() { if($id == 36) { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'")); + $row = mysql_fetch_assoc(mysql_query("select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'")); $_REQUEST['general'] = $row['general']; $_REQUEST['country'] = $row['country']; $_REQUEST['regional'] = $row['regional']; @@ -2510,7 +2510,7 @@ function buildSubjectFromSession() { if($oldid == 36) { - $rc = mysqli_num_rows(mysqli_query($_SESSION['mconn'],"select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'")); + $rc = mysql_num_rows(mysql_query("select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'")); if($rc > 0) { $query = "update `alerts` set `general`='".intval(array_key_exists('general',$_REQUEST)?$_REQUEST['general']:0)."', @@ -2525,7 +2525,7 @@ function buildSubjectFromSession() { `radius`='".intval(array_key_exists('radius',$_REQUEST)?$_REQUEST['radius']:0)."', `memid`='".intval($_SESSION['profile']['id'])."'"; } - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); $id = $oldid; $oldid=0; } @@ -2533,12 +2533,12 @@ function buildSubjectFromSession() { if($oldid == 41 && $_REQUEST['action'] == 'default') { csrf_check("mainlang"); - $lang = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['lang']); + $lang = mysql_real_escape_string($_REQUEST['lang']); foreach(L10n::$translations as $key => $val) { if($key == $lang) { - mysqli_query($_SESSION['mconn'],"update `users` set `language`='$lang' where `id`='".intval($_SESSION['profile']['id'])."'"); + mysql_query("update `users` set `language`='$lang' where `id`='".intval($_SESSION['profile']['id'])."'"); $_SESSION['profile']['language'] = $lang; showheader(_("My CAcert.org Account!")); echo _("Your language setting has been updated."); @@ -2556,9 +2556,9 @@ function buildSubjectFromSession() { if($oldid == 41 && $_REQUEST['action'] == 'addsec') { csrf_check("seclang"); - $addlang = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['addlang']); + $addlang = mysql_real_escape_string($_REQUEST['addlang']); // Does the language exist? - mysqli_query($_SESSION['mconn'],"insert into `addlang` set `userid`='".intval($_SESSION['profile']['id'])."', `lang`='$addlang'"); + mysql_query("insert into `addlang` set `userid`='".intval($_SESSION['profile']['id'])."', `lang`='$addlang'"); showheader(_("My CAcert.org Account!")); echo _("Your language setting has been updated."); showfooter(); @@ -2568,8 +2568,8 @@ function buildSubjectFromSession() { if($oldid == 41 && $_REQUEST['action'] == 'dellang') { csrf_check("seclang"); - $remove = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['remove']); - mysqli_query($_SESSION['mconn'],"delete from `addlang` where `userid`='".intval($_SESSION['profile']['id'])."' and `lang`='$remove'"); + $remove = mysql_real_escape_string($_REQUEST['remove']); + mysql_query("delete from `addlang` where `userid`='".intval($_SESSION['profile']['id'])."' and `lang`='$remove'"); showheader(_("My CAcert.org Account!")); echo _("Your language setting has been updated."); showfooter(); @@ -2604,7 +2604,7 @@ function buildSubjectFromSession() { $regid = intval(array_key_exists('regid',$_REQUEST)?$_REQUEST['regid']:0); $newreg = intval(array_key_exists('newreg',$_REQUEST)?$_REQUEST['newreg']:0); $locid = intval(array_key_exists('locid',$_REQUEST)?$_REQUEST['locid']:0); - $name = array_key_exists('name',$_REQUEST)?mysqli_real_escape_string($_SESSION['mconn'], strip_tags($_REQUEST['name'])):""; + $name = array_key_exists('name',$_REQUEST)?mysql_real_escape_string(strip_tags($_REQUEST['name'])):""; $long = array_key_exists('longitude',$_REQUEST)?ereg_replace("[^-0-9\.]","",$_REQUEST['longitude']):""; $lat = array_key_exists('latitude', $_REQUEST)?ereg_replace("[^-0-9\.]","",$_REQUEST['latitude']):""; $action = array_key_exists('action',$_REQUEST)?$_REQUEST['action']:""; @@ -2612,58 +2612,58 @@ function buildSubjectFromSession() { if($locid > 0 && $action == "edit") { $query = "update `locations` set `name`='$name', `lat`='$lat', `long`='$long' where `id`='$locid'"; - mysqli_query($_SESSION['mconn'],$query); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'")); + mysql_query($query); + $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'")); $_REQUEST['regid'] = $row['regid']; unset($_REQUEST['ccid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($regid > 0 && $action == "edit") { $query = "update `regions` set `name`='$name' where `id`='$regid'"; - mysqli_query($_SESSION['mconn'],$query); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `regions` where `id`='$regid'")); + mysql_query($query); + $row = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'")); $_REQUEST['ccid'] = $row['ccid']; unset($_REQUEST['regid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($regid > 0 && $action == "add") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select `ccid` from `regions` where `id`='$regid'")); + $row = mysql_fetch_assoc(mysql_query("select `ccid` from `regions` where `id`='$regid'")); $ccid = $row['ccid']; $query = "insert into `locations` set `ccid`='$ccid', `regid`='$regid', `name`='$name', `lat`='$lat', `long`='$long'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); unset($_REQUEST['ccid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($ccid > 0 && $action == "add" && $name != "") { $query = "insert into `regions` set `ccid`='$ccid', `name`='$name'"; - mysqli_query($_SESSION['mconn'],$query); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'")); + mysql_query($query); + $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'")); unset($_REQUEST['regid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($locid > 0 && $action == "delete") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'")); + $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'")); $_REQUEST['regid'] = $row['regid']; - mysqli_query($_SESSION['mconn'],"delete from `localias` where `locid`='$locid'"); - mysqli_query($_SESSION['mconn'],"delete from `locations` where `id`='$locid'"); + mysql_query("delete from `localias` where `locid`='$locid'"); + mysql_query("delete from `locations` where `id`='$locid'"); unset($_REQUEST['ccid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($locid > 0 && $action == "move") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'")); + $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'")); $oldregid = $row['regid']; - mysqli_query($_SESSION['mconn'],"update `locations` set `regid`='$newreg' where `id`='$locid'"); - mysqli_query($_SESSION['mconn'],"update `users` set `regid`='$newreg' where `regid`='$oldregid'"); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'")); + mysql_query("update `locations` set `regid`='$newreg' where `id`='$locid'"); + mysql_query("update `users` set `regid`='$newreg' where `regid`='$oldregid'"); + $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'")); $_REQUEST['regid'] = $row['regid']; unset($_REQUEST['ccid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); } else if($regid > 0 && $action == "delete") { - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `regions` where `id`='$regid'")); + $row = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'")); $_REQUEST['ccid'] = $row['ccid']; - mysqli_query($_SESSION['mconn'],"delete from `locations` where `regid`='$regid'"); - mysqli_query($_SESSION['mconn'],"delete from `regions` where `id`='$regid'"); + mysql_query("delete from `locations` where `regid`='$regid'"); + mysql_query("delete from `regions` where `id`='$regid'"); unset($_REQUEST['regid']); unset($_REQUEST['locid']); unset($_REQUEST['action']); @@ -2672,12 +2672,12 @@ function buildSubjectFromSession() { $_REQUEST['action'] = "aliases"; $_REQUEST['locid'] = $locid; $name = htmlentities($name); - $row = mysqli_query($_SESSION['mconn'],"insert into `localias` set `locid`='$locid',`name`='$name'"); + $row = mysql_query("insert into `localias` set `locid`='$locid',`name`='$name'"); } else if($locid > 0 && $action == "delalias") { $id = 54; $_REQUEST['action'] = "aliases"; $_REQUEST['locid'] = $locid; - $row = mysqli_query($_SESSION['mconn'],"delete from `localias` where `locid`='$locid' and `name`='$name'"); + $row = mysql_query("delete from `localias` where `locid`='$locid' and `name`='$name'"); } } @@ -2714,15 +2714,15 @@ function buildSubjectFromSession() { showfooter(); exit; } - $fname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['fname']); - $mname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['mname']); - $lname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['lname']); - $suffix = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['suffix']); + $fname = mysql_real_escape_string($_REQUEST['fname']); + $mname = mysql_real_escape_string($_REQUEST['mname']); + $lname = mysql_real_escape_string($_REQUEST['lname']); + $suffix = mysql_real_escape_string($_REQUEST['suffix']); $day = intval($_REQUEST['day']); $month = intval($_REQUEST['month']); $year = intval($_REQUEST['year']); $query = "update `users` set `fname`='$fname',`mname`='$mname',`lname`='$lname',`suffix`='$suffix',`dob`='$year-$month-$day' where `id`='$userid'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); }elseif($oldid == 43 && $actionrequest == "updatedob" && $ticketvalidation == FALSE){ $id = 43; $oldid=0; @@ -2761,7 +2761,7 @@ function buildSubjectFromSession() { if($id == 44) { $_REQUEST['userid'] = intval($_REQUEST['userid']); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); + $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); if($row['email'] == "") $id = 42; else @@ -2781,8 +2781,8 @@ function buildSubjectFromSession() { showfooter(); exit; } - mysqli_query($_SESSION['mconn'],"update `users` set `password`=sha1('".mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newpass']))."') where `id`='".intval($_REQUEST['userid'])."'"); - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); + mysql_query("update `users` set `password`=sha1('".mysql_real_escape_string(stripslashes($_REQUEST['newpass']))."') where `id`='".intval($_REQUEST['userid'])."'"); + $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); printf(_("The password for %s has been updated successfully in the system."), sanitizeHTML($row['email'])); $my_translation = L10n::get_translation(); @@ -2872,24 +2872,24 @@ function buildSubjectFromSession() { `CN`='".$_SESSION['_config']['0.CN']."', `domid`='".$_SESSION['_config']['row']['id']."', `created`=NOW()"; - mysqli_query($_SESSION['mconn'],$query); - $CSRid = mysqli_insert_id($_SESSION['mconn']); + mysql_query($query); + $CSRid = mysql_insert_id(); foreach($_SESSION['_config']['rowid'] as $dom) - mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'"); + mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'"); if(is_array($_SESSION['_config']['altid'])) foreach($_SESSION['_config']['altid'] as $dom) - mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'"); + mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'"); $CSRname=generatecertpath("csr","server",$CSRid); $fp = fopen($CSRname, "w"); fputs($fp, $_SESSION['_config']['CSR']); fclose($fp); - mysqli_query($_SESSION['mconn'],"update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'"); + mysql_query("update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'"); waitForResult("domaincerts", $CSRid,$oldid); $query = "select * from `domaincerts` where `id`='$CSRid' and `crt_name` != ''"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { showheader(_("My CAcert.org Account!")); printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", ""); @@ -2913,9 +2913,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['tverify']; - mysqli_query($_SESSION['mconn'],"update `users` set `tverify`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `tverify`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('tverify',$_REQUEST) && $_REQUEST['tverify'] > 0 && $ticketvalidation==FALSE){ $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; } @@ -2932,9 +2932,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['assurer']; - mysqli_query($_SESSION['mconn'],"update `users` set `assurer`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `assurer`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('assurer',$_REQUEST) && $_REQUEST['assurer'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['assurer']); $_SESSION['ticketmsg']='No action (Change assurer status) taken. Ticket number is missing!'; @@ -2950,9 +2950,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['assurer_blocked']; - mysqli_query($_SESSION['mconn'],"update `users` set `assurer_blocked`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `assurer_blocked`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('assurer_blocked',$_REQUEST) && $_REQUEST['assurer_blocked'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['assurer_blocked']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -2969,9 +2969,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['locked']; - mysqli_query($_SESSION['mconn'],"update `users` set `locked`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `locked`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('locked',$_REQUEST) && $_REQUEST['locked'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['locked']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -2988,9 +2988,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['codesign']; - mysqli_query($_SESSION['mconn'],"update `users` set `codesign`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `codesign`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('codesign',$_REQUEST) && $_REQUEST['codesign'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['codesign']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3007,9 +3007,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['orgadmin']; - mysqli_query($_SESSION['mconn'],"update `users` set `orgadmin`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `orgadmin`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('orgadmin',$_REQUEST) && $_REQUEST['orgadmin'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['orgadmin']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3026,9 +3026,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['ttpadmin']; - mysqli_query($_SESSION['mconn'],"update `users` set `ttpadmin`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `ttpadmin`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('ttpadmin',$_REQUEST) && $_REQUEST['ttpadmin'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['ttpadmin']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3044,11 +3044,11 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = $row['adadmin'] + 1; if($ver > 2) $ver = 0; - mysqli_query($_SESSION['mconn'],"update `users` set `adadmin`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `adadmin`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('adadmin',$_REQUEST) && $_REQUEST['adadmin'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['adadmin']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3064,9 +3064,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['locadmin']; - mysqli_query($_SESSION['mconn'],"update `users` set `locadmin`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `locadmin`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('locadmin',$_REQUEST) && $_REQUEST['locadmin'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['locadmin']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3083,9 +3083,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `users` where `id`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['admin']; - mysqli_query($_SESSION['mconn'],"update `users` set `admin`='$ver' where `id`='$memid'"); + mysql_query("update `users` set `admin`='$ver' where `id`='$memid'"); }elseif($id == 43 && array_key_exists('admin',$_REQUEST) && $_REQUEST['admin'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['admin']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3101,9 +3101,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `alerts` where `memid`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['general']; - mysqli_query($_SESSION['mconn'],"update `alerts` set `general`='$ver' where `memid`='$memid'"); + mysql_query("update `alerts` set `general`='$ver' where `memid`='$memid'"); }elseif($id == 43 && array_key_exists('general',$_REQUEST) && $_REQUEST['general'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['general']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3119,9 +3119,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `alerts` where `memid`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['country']; - mysqli_query($_SESSION['mconn'],"update `alerts` set `country`='$ver' where `memid`='$memid'"); + mysql_query("update `alerts` set `country`='$ver' where `memid`='$memid'"); }elseif($id == 43 && array_key_exists('country',$_REQUEST) && $_REQUEST['country'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['country']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3137,9 +3137,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `alerts` where `memid`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['regional']; - mysqli_query($_SESSION['mconn'],"update `alerts` set `regional`='$ver' where `memid`='$memid'"); + mysql_query("update `alerts` set `regional`='$ver' where `memid`='$memid'"); }elseif($id == 43 && array_key_exists('regional',$_REQUEST) && $_REQUEST['regional'] > 0 && $ticketvalidation == FALSE){ $_REQUEST['userid'] = intval($_REQUEST['regional']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3155,9 +3155,9 @@ function buildSubjectFromSession() { exit; } $query = "select * from `alerts` where `memid`='$memid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query)); + $row = mysql_fetch_assoc(mysql_query($query)); $ver = !$row['radius']; - mysqli_query($_SESSION['mconn'],"update `alerts` set `radius`='$ver' where `memid`='$memid'"); + mysql_query("update `alerts` set `radius`='$ver' where `memid`='$memid'"); }elseif($id == 43 && array_key_exists('radius',$_REQUEST) && $_REQUEST['radius'] > 0 && $ticketvalidation == false){ $_REQUEST['userid'] = intval($_REQUEST['radius']); $_SESSION['ticketmsg']='No action taken. Ticket number is missing!'; @@ -3169,7 +3169,7 @@ function buildSubjectFromSession() { $_REQUEST['userid'] = intval($_REQUEST['userid']); } - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); + $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'")); if($row['email'] == "") { $id = 42; } else { diff --git a/includes/account_stuff.php b/includes/account_stuff.php index 71314d1..0fda2f1 100644 --- a/includes/account_stuff.php +++ b/includes/account_stuff.php @@ -206,7 +206,7 @@ function hideall() {

+

- 0 || $_SESSION['profile']['orgadmin'] == 1) { ?> + 0 || $_SESSION['profile']['orgadmin'] == 1) { ?> - 0 || $_SESSION['profile']['orgadmin'] == 1) { ?> + 0 || $_SESSION['profile']['orgadmin'] == 1) { ?> diff --git a/includes/lib/account.php b/includes/lib/account.php index 26a29ce..dd8afd3 100644 --- a/includes/lib/account.php +++ b/includes/lib/account.php @@ -55,7 +55,7 @@ function fix_assurer_flag($userID = NULL) AND `n`.`deleted` = 0 ) >= 100'; - $query = mysqli_query($_SESSION['mconn'], $sql); + $query = mysql_query($sql); if (!$query) { return false; } @@ -91,7 +91,7 @@ function fix_assurer_flag($userID = NULL) ) < 100 )'; - $query = mysqli_query($_SESSION['mconn'], $sql); + $query = mysql_query($sql); if (!$query) { return false; } diff --git a/includes/lib/general.php b/includes/lib/general.php index 0ba4314..127c6b7 100644 --- a/includes/lib/general.php +++ b/includes/lib/general.php @@ -32,15 +32,15 @@ function get_user_id_from_cert($serial, $issuer_cn) { $query = "select `memid` from `emailcerts` where - `serial`='".mysqli_real_escape_string($_SESSION['mconn'], $serial)."' and + `serial`='".mysql_escape_string($serial)."' and `rootcert`= (select `id` from `root_certs` where - `Cert_Text`='".mysqli_real_escape_string($_SESSION['mconn'], $issuer_cn)."') and + `Cert_Text`='".mysql_escape_string($issuer_cn)."') and `revoked`=0 and disablelogin=0 and UNIX_TIMESTAMP(`expire`) - UNIX_TIMESTAMP() > 0"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) > 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); return intval($row['memid']); } @@ -139,21 +139,21 @@ function runCommand($command, $input = "", &$output = null, &$errors = true) { function get_assurer_status($userID) { $Result = 0; - $query = mysqli_query($_SESSION['mconn'], 'SELECT * FROM `cats_passed` AS `tp`, `cats_variant` AS `cv` '. + $query = mysql_query('SELECT * FROM `cats_passed` AS `tp`, `cats_variant` AS `cv` '. ' WHERE `tp`.`variant_id` = `cv`.`id` AND `cv`.`type_id` = 1 AND `tp`.`user_id` = \''.(int)intval($userID).'\''); - if(mysqli_num_rows($query) < 1) + if(mysql_num_rows($query) < 1) { $Result |= 5; } - $query = mysqli_query($_SESSION['mconn'], 'SELECT SUM(`points`) AS `points` FROM `notary` AS `n` WHERE `n`.`to` = \''.(int)intval($userID).'\' AND `n`.`expire` < now() and `deleted` = 0'); - $row = mysqli_fetch_assoc($query); + $query = mysql_query('SELECT SUM(`points`) AS `points` FROM `notary` AS `n` WHERE `n`.`to` = \''.(int)intval($userID).'\' AND `n`.`expire` < now() and `deleted` = 0'); + $row = mysql_fetch_assoc($query); if ($row['points'] < 100) { $Result |= 3; } - $query = mysqli_query($_SESSION['mconn'], 'SELECT `assurer_blocked` FROM `users` WHERE `id` = \''.(int)intval($userID).'\''); - $row = mysqli_fetch_assoc($query); + $query = mysql_query('SELECT `assurer_blocked` FROM `users` WHERE `id` = \''.(int)intval($userID).'\''); + $row = mysql_fetch_assoc($query); if ($row['assurer_blocked'] > 0) { $Result |= 9; } diff --git a/includes/lib/l10n.php b/includes/lib/l10n.php index 23b21b8..4859946 100644 --- a/includes/lib/l10n.php +++ b/includes/lib/l10n.php @@ -170,7 +170,7 @@ class L10n { foreach($languages as $lang => $qvalue) { // ignore any non-conforming values (that's why we don't need to - // mysqli_real_escape_string($_SESSION['mconn'], ) or escapeshellarg(), but take care of + // mysql_real_escape() or escapeshellarg(), but take care of // the '*') // spec: ( ( 1*8ALPHA *( "-" 1*8ALPHA ) ) | "*" ) if ( preg_match('/^(?:([a-zA-Z]{1,8})(?:-[a-zA-Z]{1,8})*|\*)$/', @@ -360,9 +360,9 @@ class L10n { //returns the language of a recipient to make sure that the language is correct //use together with $query = "select `language` from `users` where `id`='".intval($accountid)."'"; - $res = mysqli_query($_SESSION['mconn'], $query); - if (mysqli_num_rows($res)>=0) { - $row = mysqli_fetch_assoc($res); + $res = mysql_query($query); + if (mysql_num_rows($res)>=0) { + $row = mysql_fetch_assoc($res); if (NULL==$row['language'] || $row['language']=='') { self::set_translation('en'); } else { diff --git a/includes/loggedin.php b/includes/loggedin.php index 5bf157a..c14f8c2 100644 --- a/includes/loggedin.php +++ b/includes/loggedin.php @@ -44,7 +44,7 @@ //session_unregister($key); } - $_SESSION['profile'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `users` where `id`='".intval($uid)."'")); + $_SESSION['profile'] = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($uid)."'")); if($_SESSION['profile']['locked'] == 0) $_SESSION['profile']['loggedin'] = 1; else @@ -70,7 +70,7 @@ //session_unregister($key); } - $_SESSION['profile'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], + $_SESSION['profile'] = mysql_fetch_assoc(mysql_query( "select * from `users` where `id`='".intval($user_id)."'")); if($_SESSION['profile']['locked'] == 0) $_SESSION['profile']['loggedin'] = 1; @@ -103,15 +103,15 @@ if($_SERVER['HTTP_HOST'] == $_SESSION['_config']['securehostname'] && $_SESSION['profile']['id'] > 0 && $_SESSION['profile']['loggedin'] > 0) { $query = "select sum(`points`) as `total` from `notary` where `to`='".intval($_SESSION['profile']['id'])."' and `deleted` = 0 group by `to`"; - $res = mysqli_query($_SESSION['mconn'], $query); - $row = mysqli_fetch_assoc($res); + $res = mysql_query($query); + $row = mysql_fetch_assoc($res); $_SESSION['profile']['points'] = $row['total']; if($_SESSION['profile']['language'] == "") { $query = "update `users` set `language`='".L10n::get_translation()."' where `id`='".intval($_SESSION['profile']['id'])."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); } else { L10n::set_translation($_SESSION['profile']['language']); L10n::init_gettext(); diff --git a/includes/mysql.php.sample b/includes/mysql.php.sample index befe079..77be95f 100644 --- a/includes/mysql.php.sample +++ b/includes/mysql.php.sample @@ -16,14 +16,13 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA */ - $_SESSION['mconn'] = mysqli_connect("127.0.0.1", "username", "password", "database"); - -// if (!$_SESSION['mconn']) { -// die('Connect Error (' . mysqli_connect_errno() . ') ' -// . mysqli_connect_error()); -// } - - $_SESSION['_config']['normalhostname'] = "www.cacert.org"; + $_SESSION['mconn'] = mysql_connect("127.0.0.1", "username", "password"); + if ($_SESSION['mconn'] != FALSE) + { + mysql_select_db("database"); + $_SESSION['mconn'] = TRUE; + } + $_SESSION['_config']['normalhostname'] = "www.cacert.org"; $_SESSION['_config']['securehostname'] = "secure.cacert.org"; $_SESSION['_config']['tverify'] = "tverify.cacert.org"; diff --git a/includes/notary.inc.php b/includes/notary.inc.php index a4c8ee7..3b8e736 100644 --- a/includes/notary.inc.php +++ b/includes/notary.inc.php @@ -21,18 +21,18 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function query_init ($query) { - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } function query_getnextrow ($res) { - $row1 = mysqli_fetch_assoc($res); + $row1 = mysql_fetch_assoc($res); return $row1; } function query_get_number_of_rows ($resultset) { - return intval(mysqli_num_rows($resultset)); + return intval(mysql_num_rows($resultset)); } function get_number_of_assurances ($userid) @@ -125,7 +125,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function get_user ($userid) { $res = query_init ("select * from `users` where `id`='".intval($userid)."'"); - return mysqli_fetch_assoc($res); + return mysql_fetch_assoc($res); } function get_cats_state ($userid) @@ -133,7 +133,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); $res = query_init ("select * from `cats_passed` inner join `cats_variant` on `cats_passed`.`variant_id` = `cats_variant`.`id` and `cats_variant`.`type_id` = 1 WHERE `cats_passed`.`user_id` = '".intval($userid)."'"); - return mysqli_num_rows($res); + return mysql_num_rows($res); } @@ -587,7 +587,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); $sum_points = 0; $sumexperience = 0; $res = get_given_assurances(intval($userid), $log); - while($row = mysqli_fetch_assoc($res)) + while($row = mysql_fetch_assoc($res)) { $assuree = get_user(intval($row['to'])); calc_experience($row, $sum_points, $sum_experience); @@ -617,7 +617,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); $sum_points = 0; $sumexperience = 0; $res = get_received_assurances(intval($userid), $log); - while($row = mysqli_fetch_assoc($res)) + while($row = mysql_fetch_assoc($res)) { $fromuser = get_user(intval($row['from'])); calc_assurances($row, $sum_points, $sum_experience); @@ -661,7 +661,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); } $res = get_received_assurances_summary($userid); - while($row = mysqli_fetch_assoc($res)) + while($row = mysql_fetch_assoc($res)) { $points = calc_awarded($row); @@ -674,7 +674,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); } $res = get_given_assurances_summary($userid); - while($row = mysqli_fetch_assoc($res)) + while($row = mysql_fetch_assoc($res)) { switch ($row['method']) { @@ -860,8 +860,8 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function write_user_agreement($memid, $document, $method, $comment, $active=1, $secmemid=0){ // write a new record to the table user_agreement $query="insert into `user_agreements` set `memid`=".intval($memid).", `secmemid`=".intval($secmemid). - ",`document`='".mysqli_real_escape_string($_SESSION['mconn'], $document)."',`date`=NOW(), `active`=".intval($active).",`method`='".mysqli_real_escape_string($_SESSION['mconn'], $method)."',`comment`='".mysqli_real_escape_string($_SESSION['mconn'], $comment)."'" ; - $res = mysqli_query($_SESSION['mconn'], $query); + ",`document`='".mysql_real_escape_string($document)."',`date`=NOW(), `active`=".intval($active).",`method`='".mysql_real_escape_string($method)."',`comment`='".mysql_real_escape_string($comment)."'" ; + $res = mysql_query($query); } /** @@ -873,9 +873,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); */ function get_user_agreement_status($memid, $type="CCA"){ $query="SELECT u.`document` FROM `user_agreements` u - WHERE u.`document` = '" . mysqli_real_escape_string($_SESSION['mconn'], $type) . "' AND u.`memid`=" . intval($memid) ; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <=0){ + WHERE u.`document` = '" . mysql_real_escape_string($type) . "' AND u.`memid`=" . intval($memid) ; + $res = mysql_query($query); + if(mysql_num_rows($res) <=0){ return 0; }else{ return 1; @@ -897,7 +897,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function get_first_user_agreement($memid, $type=null, $active=null){ $filter = ''; if (!is_null($type)) { - $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'"; + $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'"; } if (!is_null($active)) { @@ -908,9 +908,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); WHERE u.`memid`=".intval($memid)." $filter ORDER BY u.`date` LIMIT 1"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) >0){ - $rec = mysqli_fetch_assoc($res); + $res = mysql_query($query); + if(mysql_num_rows($res) >0){ + $rec = mysql_fetch_assoc($res); }else{ $rec=array(); } @@ -932,7 +932,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function get_last_user_agreement($memid, $type=null, $active=null){ $filter = ''; if (!is_null($type)) { - $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'"; + $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'"; } if (!is_null($active)) { @@ -943,9 +943,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); WHERE u.`memid`=".intval($memid)." $filter ORDER BY u.`date` DESC LIMIT 1"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) >0){ - $rec = mysqli_fetch_assoc($res); + $res = mysql_query($query); + if(mysql_num_rows($res) >0){ + $rec = mysql_fetch_assoc($res); }else{ $rec=array(); } @@ -966,7 +966,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00'); function get_user_agreements($memid, $type=null, $active=null){ $filter = ''; if (!is_null($type)) { - $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'"; + $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'"; } if (!is_null($active)) { @@ -977,7 +977,7 @@ function get_user_agreements($memid, $type=null, $active=null){ WHERE u.`memid`=".intval($memid)." $filter ORDER BY u.`date`"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -991,9 +991,9 @@ function get_user_agreements($memid, $type=null, $active=null){ if ($type === false) { $filter = ''; } else { - $filter = " and `document` = '" . mysqli_real_escape_string($_SESSION['mconn'], $type) . "'"; + $filter = " and `document` = '" . mysql_real_escape_string($type) . "'"; } - mysqli_query($_SESSION['mconn'], "delete from `user_agreements` where `memid`=" . intval($memid) . $filter ); + mysql_query("delete from `user_agreements` where `memid`=" . intval($memid) . $filter ); } // functions for 6.php (assure somebody) @@ -1095,7 +1095,7 @@ function get_user_agreements($memid, $type=null, $active=null){ $mailid = intval($mailid); revoke_all_client_cert($mailid); $query = "update `email` set `deleted`=NOW() where `id`='$mailid'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); } function account_domain_delete($domainid){ @@ -1106,7 +1106,7 @@ function get_user_agreements($memid, $type=null, $active=null){ //called from account_delete $domainid = intval($domainid); revoke_all_server_cert($domainid); - mysqli_query($_SESSION['mconn'], + mysql_query( "update `domains` set `deleted`=NOW() where `id` = '$domainid'"); @@ -1117,7 +1117,7 @@ function get_user_agreements($memid, $type=null, $active=null){ // called from www/account.php if($oldid == 50 && $process != "") //change password $id = intval($id); - $arbno = mysqli_real_escape_string($_SESSION['mconn'], $arbno); + $arbno = mysql_real_escape_string($arbno); $adminid = intval($adminid); $pool = 'abcdefghijklmnopqrstuvwxyz'; $pool .= '0123456789!()§'; @@ -1128,33 +1128,33 @@ function get_user_agreements($memid, $type=null, $active=null){ { $password .= substr($pool,(rand()%(strlen ($pool))), 1); } - mysqli_query($_SESSION['mconn'], "update `users` set `password`=sha1('".$password."') where `id`='".$id."'"); + mysql_query("update `users` set `password`=sha1('".$password."') where `id`='".$id."'"); //create new mail for arbitration number $query = "insert into `email` set `email`='".$arbno."@cacert.org',`memid`='".$id."',`created`=NOW(),`modified`=NOW(), `attempts`=-1"; - mysqli_query($_SESSION['mconn'], $query); - $emailid = mysqli_insert_id($_SESSION['mconn']); + mysql_query($query); + $emailid = mysql_insert_id(); //set new mail as default $query = "update `users` set `email`='".$arbno."@cacert.org' where `id`='".$id."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); //delete all other email address $query = "select `id` from `email` where `memid`='".$id."' and `id`!='".$emailid."'" ; - $res=mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)){ + $res=mysql_query($query); + while($row = mysql_fetch_assoc($res)){ account_email_delete($row['id']); } //delete all domains $query = "select `id` from `domains` where `memid`='".$id."'"; - $res=mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)){ + $res=mysql_query($query); + while($row = mysql_fetch_assoc($res)){ account_domain_delete($row['id']); } //clear alert settings - mysqli_query($_SESSION['mconn'], + mysql_query( "update `alerts` set `general`='0', `country`='0', @@ -1164,17 +1164,17 @@ function get_user_agreements($memid, $type=null, $active=null){ //set default location $query = "update `users` set `locid`='2256755', `regid`='243', `ccid`='12' where `id`='".$id."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); //clear listings $query = "update `users` set `listme`=' ',`contactinfo`=' ' where `id`='".$id."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); //set lanuage to default //set default language - mysqli_query($_SESSION['mconn'], "update `users` set `language`='en_AU' where `id`='".$id."'"); + mysql_query("update `users` set `language`='en_AU' where `id`='".$id."'"); //delete secondary langugaes - mysqli_query($_SESSION['mconn'], "delete from `addlang` where `userid`='".$id."'"); + mysql_query("delete from `addlang` where `userid`='".$id."'"); //change secret questions for($i=1;$i<=5;$i++){ @@ -1186,7 +1186,7 @@ function get_user_agreements($memid, $type=null, $active=null){ $a .= substr($pool,(rand()%(strlen ($pool))), 1); } $query = "update `users` set `Q$i`='$q', `A$i`='$a' where `id`='".$id."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); } //change personal information to arbitration number and DOB=1900-01-01 @@ -1196,10 +1196,10 @@ function get_user_agreements($memid, $type=null, $active=null){ `suffix`='".$arbno."', `dob`='1900-01-01' where `id`='".$id."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); //clear all admin and board flags - mmysqli_query($_SESSION['mconn'], + mysql_query( "update `users` set `assurer`='0', `assurer_blocked`='0', @@ -1214,17 +1214,17 @@ function get_user_agreements($memid, $type=null, $active=null){ where `id`='$id'"); //block account - mysqli_query($_SESSION['mconn'], "update `users` set `locked`='1' where `id`='$id'"); //, `deleted`=Now() + mysql_query("update `users` set `locked`='1' where `id`='$id'"); //, `deleted`=Now() } function check_email_exists($email){ // called from includes/account.php if($process != "" && $oldid == 1) // called from includes/account.php if($oldid == 50 && $process != "") - $email = mysqli_real_escape_string($_SESSION['mconn'], $email); + $email = mysql_real_escape_string($email); $query = "select 1 from `email` where `email`='$email' and `deleted`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - return mysqli_num_rows($res) > 0; + $res = mysql_query($query); + return mysql_num_rows($res) > 0; } function check_gpg_cert_running($uid,$cca=0){ @@ -1236,8 +1236,8 @@ function get_user_agreements($memid, $type=null, $active=null){ }else{ $query = "select 1 from `gpg` where `memid`='$uid' and `expire`>(NOW()-90*86400)"; } - $res = mysqli_query($_SESSION['mconn'], $query); - return mysqli_num_rows($res) > 0; + $res = mysql_query($query); + return mysql_num_rows($res) > 0; } function check_client_cert_running($uid,$cca=0){ @@ -1251,10 +1251,10 @@ function get_user_agreements($memid, $type=null, $active=null){ $query1 = "select 1 from `emailcerts` where `memid`='$uid' and `expire`>(NOW()-90*86400) and `revoked`<`created`"; $query2 = "select 1 from `emailcerts` where `memid`='$uid' and `revoked`>(NOW()-90*86400)"; } - $res = mysqli_query($_SESSION['mconn'], $query1); - $r1 = mysqli_num_rows($res)>0; - $res = mysqli_query($_SESSION['mconn'], $query2); - $r2 = mysqli_num_rows($res)>0; + $res = mysql_query($query1); + $r1 = mysql_num_rows($res)>0; + $res = mysql_query($query2); + $r2 = mysql_num_rows($res)>0; return !!($r1 || $r2); } @@ -1287,10 +1287,10 @@ function get_user_agreements($memid, $type=null, $active=null){ where `domains`.`memid` = '$uid' and `revoked`>(NOW()-90*86400)"; } - $res = mysqli_query($_SESSION['mconn'], $query1); - $r1 = mysqli_num_rows($res)>0; - $res = mysqli_query($_SESSION['mconn'], $query2); - $r2 = mysqli_num_rows($res)>0; + $res = mysql_query($query1); + $r1 = mysql_num_rows($res)>0; + $res = mysql_query($query2); + $r2 = mysql_num_rows($res)>0; return !!($r1 || $r2); } @@ -1298,8 +1298,8 @@ function get_user_agreements($memid, $type=null, $active=null){ // called from includes/account.php if($oldid == 50 && $process != "") $uid = intval($uid); $query = "select 1 from `org` where `memid`='$uid' and `deleted`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - return mysqli_num_rows($res) > 0; + $res = mysql_query($query); + return mysql_num_rows($res) > 0; } @@ -1311,9 +1311,9 @@ function get_user_agreements($memid, $type=null, $active=null){ from `emaillink`,`emailcerts` where `emaillink`.`emailid`='$mailid' and `emaillink`.`emailcertsid`=`emailcerts`.`id` and `emailcerts`.`revoked`=0 group by `emailcerts`.`id`"; - $dres = mysqli_query($_SESSION['mconn'], $query); - while($drow = mysqli_fetch_assoc($dres)){ - mysqli_query($_SESSION['mconn'], "update `emailcerts` set `revoked`='1970-01-01 10:00:01', `disablelogin`=1 where `id`='".$drow['id']."'"); + $dres = mysql_query($query); + while($drow = mysql_fetch_assoc($dres)){ + mysql_query("update `emailcerts` set `revoked`='1970-01-01 10:00:01', `disablelogin`=1 where `id`='".$drow['id']."'"); } } @@ -1329,10 +1329,10 @@ function get_user_agreements($memid, $type=null, $active=null){ from `domaincerts`, `domlink` where `domaincerts`.`id` = `domlink`.`certid` and `domlink`.`domid` = '$domainid'"; - $dres = mysqli_query($_SESSION['mconn'], $query); - while($drow = mysqli_fetch_assoc($dres)) + $dres = mysql_query($query); + while($drow = mysql_fetch_assoc($dres)) { - mysqli_query($_SESSION['mconn'], + mysql_query( "update `domaincerts` set `revoked`='1970-01-01 10:00:01' where `id` = '".$drow['id']."' @@ -1345,15 +1345,15 @@ function get_user_agreements($memid, $type=null, $active=null){ //gpg revokation needs to be added to a later point $uid=intval($uid); $query = "select `id` from `email` where `memid`='".$uid."'"; - $res=mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)){ + $res=mysql_query($query); + while($row = mysql_fetch_assoc($res)){ revoke_all_client_cert($row['id']); } $query = "select `id` from `domains` where `memid`='".$uid."'"; - $res=mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)){ + $res=mysql_query($query); + while($row = mysql_fetch_assoc($res)){ revoke_all_server_cert($row['id']); } } @@ -1415,11 +1415,11 @@ function write_se_log($uid, $adminid, $type, $info){ //records all support engineer actions changing a user account $uid = intval($uid); $adminid = intval($adminid); - $type = mysqli_real_escape_string($_SESSION['mconn'], $type); - $info = mysqli_real_escape_string($_SESSION['mconn'], g($info); + $type = mysql_real_escape_string($type); + $info = mysql_real_escape_string($info); $query="insert into `adminlog` (`when`, `uid`, `adminid`,`type`,`information`) values (Now(), $uid, $adminid, '$type', '$info')"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1453,7 +1453,7 @@ function get_user_data($userid, $deleted=0){ $filter .=' and `users`.`deleted`=0'; } $query = "select * from `users` where `users`.`id`='$userid' ".$filter; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1462,7 +1462,7 @@ function get_user_data($userid, $deleted=0){ * @return array - associative array */ function get_alerts($userid){ - return mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `alerts` where `memid`='".intval($userid)."'")); + return mysql_fetch_assoc(mysql_query("select * from `alerts` where `memid`='".intval($userid)."'")); } /** @@ -1480,10 +1480,10 @@ function get_email_addresses($userid, $exclude, $deleted=0){ $filter .= ' and `deleted`=0'; } if ($exclude) { - $filter .= " and `email`!='".mysqli_real_escape_string($_SESSION['mconn'], $exclude)."'"; + $filter .= " and `email`!='".mysql_real_escape_string($exclude)."'"; } $query = "select * from `email` where `memid`='".$userid."' and `hash`='' ".$filter." order by `created`"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1500,7 +1500,7 @@ function get_domains($userid, $deleted=0){ $filter .= ' and `deleted`=0'; } $query = "select * from `domains` where `memid`='".$userid."' and `hash`=''".$filter." order by `created`"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1515,7 +1515,7 @@ function get_training_results($userid){ " FROM `cats_passed` AS CP, `cats_variant` AS CV, `cats_type` AS CT ". " WHERE `CP`.`variant_id`=`CV`.`id` AND `CV`.`type_id`=`CT`.`id` AND `CP`.`user_id` ='".$userid."'". " ORDER BY `CP`.`pass_date`"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1529,7 +1529,7 @@ function get_se_log($userid){ FROM `adminlog`, `users` WHERE `adminlog`.`adminid` = `users`.`id` and `adminlog`.`uid`=".$userid." ORDER BY `adminlog`.`when`"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1560,7 +1560,7 @@ function get_client_certs($userid, $viewall=0){ $query .= " HAVING `timeleft` > 0"; } $query .= " ORDER BY `emailcerts`.`modified` desc"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1590,7 +1590,7 @@ function get_server_certs($userid, $viewall=0){ $query .= " HAVING `timeleft` > 0"; } $query .= " ORDER BY `domaincerts`.`modified` desc"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } /** @@ -1611,7 +1611,7 @@ function get_gpg_certs($userid, $viewall=0){ $query .= " HAVING `timeleft` > 0"; } $query .= " ORDER BY `issued` desc"; - return mysqli_query($_SESSION['mconn'], $query); + return mysql_query($query); } diff --git a/pages/account/12.php b/pages/account/12.php index 234891f..f4428aa 100644 --- a/pages/account/12.php +++ b/pages/account/12.php @@ -49,15 +49,15 @@ } $query .= "ORDER BY `modified` desc"; //echo $query."
\n"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { ?> 0) $verified = _("Valid"); diff --git a/pages/account/13.php b/pages/account/13.php index 0dcf58b..ea28c0e 100644 --- a/pages/account/13.php +++ b/pages/account/13.php @@ -17,8 +17,8 @@ */ ?> diff --git a/pages/account/18.php b/pages/account/18.php index cec7a49..ca0a3c8 100644 --- a/pages/account/18.php +++ b/pages/account/18.php @@ -37,9 +37,9 @@ $status = array_key_exists('status',$_SESSION['_config']) ? intval($_SESSION['_c from `org`, `orginfo` where `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `orginfo`.`id` = `org`.`orgid` ORDER BY `orginfo`.`O` "; - $reso = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($reso) >= 1){ - while($row = mysqli_fetch_assoc($reso)){ + $reso = mysql_query($query); + if(mysql_num_rows($reso) >= 1){ + while($row = mysql_fetch_assoc($reso)){ printf('',$row['id'], $row['id'] == $orgfilterid ? " selected" : "" , $row['O']); } }?> @@ -106,8 +106,8 @@ $status = array_key_exists('status',$_SESSION['_config']) ? intval($_SESSION['_c $query .= "ORDER BY `orginfo`.`O`, `oemail`.`CN`, `modified` desc"; break; } - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { ?> @@ -116,7 +116,7 @@ $status = array_key_exists('status',$_SESSION['_config']) ? intval($_SESSION['_c $orgname) { $orgname=$row['O'];?> @@ -188,4 +188,4 @@ $status = array_key_exists('status',$_SESSION['_config']) ? intval($_SESSION['_c - + \ No newline at end of file diff --git a/pages/account/19.php b/pages/account/19.php index 0d01c6d..d7259f3 100644 --- a/pages/account/19.php +++ b/pages/account/19.php @@ -21,15 +21,15 @@ $query = "select * from `orgemailcerts`,`org` where `orgemailcerts`.`id`='".intval($certid)."' and `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orgemailcerts`.`orgid`"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { showheader(_("My CAcert.org Account!")); echo _("No such certificate attached to your account."); showfooter(); exit; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $crtname=escapeshellarg($row['crt_name']); $cert = shell_exec("/usr/bin/openssl x509 -in $crtname"); diff --git a/pages/account/2.php b/pages/account/2.php index 0894dd0..36421f9 100644 --- a/pages/account/2.php +++ b/pages/account/2.php @@ -28,8 +28,8 @@ = 1){ - while($row = mysqli_fetch_assoc($reso)){ + $reso = mysql_query($query); + if(mysql_num_rows($reso) >= 1){ + while($row = mysql_fetch_assoc($reso)){ printf('',$row['id'], $row['id'] == $orgfilterid ? " selected" : "" , $row['O']); } }?> @@ -109,8 +109,8 @@ $status = array_key_exists('dstatus',$_SESSION['_config']) ? intval($_SESSION['_ //echo $query."
\n"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { ?> @@ -118,7 +118,7 @@ $status = array_key_exists('dstatus',$_SESSION['_config']) ? intval($_SESSION['_ $orgname) { $orgname=$row['O'];?> diff --git a/pages/account/23.php b/pages/account/23.php index 33f1101..4255b47 100644 --- a/pages/account/23.php +++ b/pages/account/23.php @@ -21,14 +21,14 @@ $query = "select * from `orgdomaincerts`,`org` where `orgdomaincerts`.`id`='$certid' and `org`.`memid`='".intval($_SESSION['profile']['id'])."' and `org`.`orgid`=`orgdomaincerts`.`orgid`"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { echo _("No such certificate attached to your account."); showfooter(); exit; } - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $crtname=escapeshellarg($row['crt_name']); $cert = shell_exec("/usr/bin/openssl x509 -in $crtname"); ?> diff --git a/pages/account/25.php b/pages/account/25.php index 8241852..a70f608 100644 --- a/pages/account/25.php +++ b/pages/account/25.php @@ -54,13 +54,13 @@ // Safe because $order_by only contains fixed strings $query = sprintf("select * from `orginfo` ORDER BY %s", $order_by); - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { - $r2 = mysqli_query($_SESSION['mconn'], "select * from `org` where `orgid`='".intval($row['id'])."'"); - $admincount = mysqli_num_rows($r2); - $r2 = mysqli_query($_SESSION['mconn'], "select * from `orgdomains` where `orgid`='".intval($row['id'])."'"); - $domcount = mysqli_num_rows($r2); + $r2 = mysql_query("select * from `org` where `orgid`='".intval($row['id'])."'"); + $admincount = mysql_num_rows($r2); + $r2 = mysql_query("select * from `orgdomains` where `orgid`='".intval($row['id'])."'"); + $domcount = mysql_num_rows($r2); ?> , diff --git a/pages/account/26.php b/pages/account/26.php index 99a2bd2..f8b195d 100644 --- a/pages/account/26.php +++ b/pages/account/26.php @@ -17,7 +17,7 @@ */ ?> @@ -30,8 +30,8 @@ diff --git a/pages/account/27.php b/pages/account/27.php index 7c73be4..a1086d4 100644 --- a/pages/account/27.php +++ b/pages/account/27.php @@ -16,7 +16,7 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA */ ?>
diff --git a/pages/account/28.php b/pages/account/28.php index 7d7f7aa..1212f9c 100644 --- a/pages/account/28.php +++ b/pages/account/28.php @@ -17,7 +17,7 @@ */ ?>
diff --git a/pages/account/29.php b/pages/account/29.php index 2132826..4229b3b 100644 --- a/pages/account/29.php +++ b/pages/account/29.php @@ -17,9 +17,9 @@ */ ?> diff --git a/pages/account/3.php b/pages/account/3.php index a2d6bc0..cd62ce0 100644 --- a/pages/account/3.php +++ b/pages/account/3.php @@ -38,8 +38,8 @@ diff --git a/pages/account/30.php b/pages/account/30.php index 8cf1a03..04ad229 100644 --- a/pages/account/30.php +++ b/pages/account/30.php @@ -17,9 +17,9 @@ */ ?> diff --git a/pages/account/31.php b/pages/account/31.php index 033d177..9f3d27e 100644 --- a/pages/account/31.php +++ b/pages/account/31.php @@ -17,7 +17,7 @@ */ ?> diff --git a/pages/account/32.php b/pages/account/32.php index 6bb92ce..a05c927 100644 --- a/pages/account/32.php +++ b/pages/account/32.php @@ -17,7 +17,7 @@ */ ?>
@@ -32,10 +32,10 @@ diff --git a/pages/account/33.php b/pages/account/33.php index a8f894b..9e2f67a 100644 --- a/pages/account/33.php +++ b/pages/account/33.php @@ -17,7 +17,7 @@ */ ?> diff --git a/pages/account/35.php b/pages/account/35.php index 64f62e1..05c7f2b 100644 --- a/pages/account/35.php +++ b/pages/account/35.php @@ -24,8 +24,8 @@ $query = "select * where `orginfo`.`id`=`org`.`orgid` and `org`.`memid`='".intval($_SESSION['profile']['id'])."'"; -$res = mysqli_query($_SESSION['mconn'], $query); -while($row = mysqli_fetch_assoc($res)) +$res = mysql_query($query); +while($row = mysql_fetch_assoc($res)) { ?> @@ -55,8 +55,8 @@ while($row = mysqli_fetch_assoc($res)) //domain info $query = "select `domain` from `orgdomains` where `orgid`='".intval($row['id'])."'"; - $res1 = mysqli_query($_SESSION['mconn'], $query); - while($domain = mysqli_fetch_assoc($res1)) + $res1 = mysql_query($query); + while($domain = mysql_fetch_assoc($res1)) { ?> @@ -76,10 +76,10 @@ while($row = mysqli_fetch_assoc($res)) //org admins $query = "select * from `org` where `orgid`='".intval($row['id'])."'"; - $res2 = mysqli_query($_SESSION['mconn'], $query); - while($org = mysqli_fetch_assoc($res2)) + $res2 = mysql_query($query); + while($org = mysql_fetch_assoc($res2)) { - $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `users` where `id`='".intval($org['memid'])."'")); + $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($org['memid'])."'")); ?> diff --git a/pages/account/41.php b/pages/account/41.php index 381b0a4..d61d8db 100644 --- a/pages/account/41.php +++ b/pages/account/41.php @@ -54,10 +54,10 @@ require_once($_SESSION['_config']['filepath'].'/includes/lib/l10n.php'); @@ -70,8 +70,8 @@ require_once($_SESSION['_config']['filepath'].'/includes/lib/l10n.php');
'>
'>
: @@ -75,7 +75,7 @@ if(intval(array_key_exists('userid',$_REQUEST)?$_REQUEST['userid']:0) <= 0) @@ -85,7 +85,7 @@ if(intval(array_key_exists('userid',$_REQUEST)?$_REQUEST['userid']:0) <= 0) = 100) { + if(mysql_num_rows($res) >= 100) { ?> @@ -94,15 +94,15 @@ if(intval(array_key_exists('userid',$_REQUEST)?$_REQUEST['userid']:0) <= 0) } else { ?> - +


0) { $userid = intval($_REQUEST['userid']); $res =get_user_data($userid); - if(mysqli_num_rows($res) <= 0) { + if(mysql_num_rows($res) <= 0) { echo _("I'm sorry, the user you were looking for seems to have disappeared! Bad things are afoot!"); } else { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $query = "select sum(`points`) as `points` from `notary` where `to`='".intval($row['id'])."' and `deleted` = 0"; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $alerts =get_alerts(intval($row['id'])); //display account data @@ -132,11 +132,11 @@ if(intval($_REQUEST['userid']) > 0) { } else { $assurance = intval($_REQUEST['assurance']); $trow = 0; - $res = mysqli_query($_SESSION['mconn'], "select `to` from `notary` where `id`='".intval($assurance)."' and `deleted` = 0"); + $res = mysql_query("select `to` from `notary` where `id`='".intval($assurance)."' and `deleted` = 0"); if ($res) { - $trow = mysqli_fetch_assoc($res); + $trow = mysql_fetch_assoc($res); if ($trow) { - mysqli_query($_SESSION['mconn'], "update `notary` set `deleted`=NOW() where `id`='".intval($assurance)."'"); + mysql_query("update `notary` set `deleted`=NOW() where `id`='".intval($assurance)."'"); fix_assurer_flag($trow['to']); } } @@ -403,14 +403,14 @@ if(intval($_REQUEST['userid']) > 0) { 0) { + if(mysql_num_rows($dres) > 0) { ?> @@ -426,14 +426,14 @@ if(intval($_REQUEST['userid']) > 0) { // list of domains $dres=get_domains(intval($row['id'])); - if(mysqli_num_rows($dres) > 0) { + if(mysql_num_rows($dres) > 0) { ?>
:
@@ -488,7 +488,7 @@ if(intval($_REQUEST['userid']) > 0) { 4. users.email = primary-email --- Assurer, assure someone find user query - select * from `users` where `email`='".mysqli_real_escape_string($_SESSION['mconn'], $_POST['email']))."' + select * from `users` where `email`='".mysql_real_escape_string(stripslashes($_POST['email']))."' and `deleted`=0 => requirements 1. users.deleted = 0 @@ -527,8 +527,8 @@ if(intval($_REQUEST['userid']) > 0) { // current userid intval($row['id']) $query = "select `email` as `uemail`, `deleted` as `udeleted`, `verified`, `locked` from `users` where `id`='".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $uemail = $drow['uemail']; $udeleted = $drow['udeleted']; $uverified = $drow['verified']; @@ -538,16 +538,16 @@ if(intval($_REQUEST['userid']) > 0) { where `memid`='".intval($row['id'])."' and `email` ='".$uemail."' and `deleted` = 0"; - $dres = mysqli_query($_SESSION['mconn'], $query); - if ($drow = mysqli_fetch_assoc($dres)) { + $dres = mysql_query($query); + if ($drow = mysql_fetch_assoc($dres)) { $drow['edeleted'] = 0; } else { // try if there are deleted entries $query = "select `hash`, `deleted` as `edeleted`, `email` as `eemail` from `email` where `memid`='".intval($row['id'])."' and `email` ='".$uemail."'"; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); } if ($drow) { @@ -626,8 +626,8 @@ if(intval($_REQUEST['userid']) > 0) { on `domains`.`id` = `domaincerts`.`domid` where `domains`.`memid` = '".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $total = $drow['total']; $maxexpire = "0000-00-00 00:00:00"; @@ -644,8 +644,8 @@ if(intval($_REQUEST['userid']) > 0) { and `revoked` = '0000-00-00 00:00:00' and `expire` > NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $valid = $drow['valid']; $query = " @@ -655,8 +655,8 @@ if(intval($_REQUEST['userid']) > 0) { where `domains`.`memid` = '".intval($row['id'])."' and `expire` <= NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $expired = $drow['expired']; $query = " @@ -666,8 +666,8 @@ if(intval($_REQUEST['userid']) > 0) { where `domains`.`memid` = '".intval($row['id'])."' and `revoked` != '0000-00-00 00:00:00' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $revoked = $drow['revoked']; ?> @@ -692,8 +692,8 @@ if(intval($_REQUEST['userid']) > 0) { from `emailcerts` where `memid` = '".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $total = $drow['total']; $maxexpire = "0000-00-00 00:00:00"; @@ -709,8 +709,8 @@ if(intval($_REQUEST['userid']) > 0) { and `revoked` = '0000-00-00 00:00:00' and `expire` > NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $valid = $drow['valid']; $query = " @@ -719,8 +719,8 @@ if(intval($_REQUEST['userid']) > 0) { where `memid` = '".intval($row['id'])."' and `expire` <= NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $expired = $drow['expired']; $query = " @@ -729,8 +729,8 @@ if(intval($_REQUEST['userid']) > 0) { where `memid` = '".intval($row['id'])."' and `revoked` != '0000-00-00 00:00:00' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $revoked = $drow['revoked']; ?> @@ -755,8 +755,8 @@ if(intval($_REQUEST['userid']) > 0) { from `gpg` where `memid` = '".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $total = $drow['total']; $maxexpire = "0000-00-00 00:00:00"; @@ -771,8 +771,8 @@ if(intval($_REQUEST['userid']) > 0) { where `memid` = '".intval($row['id'])."' and `expire` > NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $valid = $drow['valid']; $query = " @@ -781,8 +781,8 @@ if(intval($_REQUEST['userid']) > 0) { where `memid` = '".intval($row['id'])."' and `expire` <= NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $expired = $drow['expired']; ?> @@ -809,8 +809,8 @@ if(intval($_REQUEST['userid']) > 0) { on `orgcerts`.`orgid` = `org`.`orgid` where `org`.`memid` = '".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $total = $drow['total']; $maxexpire = "0000-00-00 00:00:00"; @@ -827,8 +827,8 @@ if(intval($_REQUEST['userid']) > 0) { and `orgcerts`.`revoked` = '0000-00-00 00:00:00' and `orgcerts`.`expire` > NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $valid = $drow['valid']; $query = " @@ -838,8 +838,8 @@ if(intval($_REQUEST['userid']) > 0) { where `org`.`memid` = '".intval($row['id'])."' and `orgcerts`.`expire` <= NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $expired = $drow['expired']; $query = " @@ -849,8 +849,8 @@ if(intval($_REQUEST['userid']) > 0) { where `org`.`memid` = '".intval($row['id'])."' and `orgcerts`.`revoked` != '0000-00-00 00:00:00' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $revoked = $drow['revoked']; ?> @@ -877,8 +877,8 @@ if(intval($_REQUEST['userid']) > 0) { on `orgcerts`.`orgid` = `org`.`orgid` where `org`.`memid` = '".intval($row['id'])."' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $total = $drow['total']; $maxexpire = "0000-00-00 00:00:00"; @@ -895,8 +895,8 @@ if(intval($_REQUEST['userid']) > 0) { and `orgcerts`.`revoked` = '0000-00-00 00:00:00' and `orgcerts`.`expire` > NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $valid = $drow['valid']; $query = " @@ -906,8 +906,8 @@ if(intval($_REQUEST['userid']) > 0) { where `org`.`memid` = '".intval($row['id'])."' and `orgcerts`.`expire` <= NOW() "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $expired = $drow['expired']; $query = " @@ -917,8 +917,8 @@ if(intval($_REQUEST['userid']) > 0) { where `org`.`memid` = '".intval($row['id'])."' and `orgcerts`.`revoked` != '0000-00-00 00:00:00' "; - $dres = mysqli_query($_SESSION['mconn'], $query); - $drow = mysqli_fetch_assoc($dres); + $dres = mysql_query($query); + $drow = mysql_fetch_assoc($dres); $revoked = $drow['revoked']; ?> @@ -985,10 +985,10 @@ if(intval($_REQUEST['userid']) > 0) { @@ -1032,10 +1032,10 @@ if(intval($_REQUEST['userid']) > 0) { diff --git a/pages/account/49.php b/pages/account/49.php index b3b8d53..0218fa0 100644 --- a/pages/account/49.php +++ b/pages/account/49.php @@ -19,7 +19,7 @@ $userid=0; if(array_key_exists('userid',$_GET)) $userid=intval($_GET['userid']); if($userid <= 0) { - $domainsearch = $domain = mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_POST['domain'])); + $domainsearch = $domain = mysql_escape_string(stripslashes($_POST['domain'])); if(!strstr($domain, "%")) $domainsearch = "%$domain%"; if(preg_match("/^\d+$/",$domain)) @@ -30,32 +30,32 @@ `domains`.`deleted`=0 and `users`.`deleted`=0 and `users`.`verified`=1 group by `users`.`id` limit 100"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) >= 1) { ?> + $res = mysql_query($query); + if(mysql_num_rows($res) >= 1) { ?>
:
-= 100) { ?> += 100) { ?> - +
:


- @@ -66,32 +66,32 @@ } $query = "select `orgid`,`domain`,`id` from `orgdomains` where `domain` like '$domainsearch' or `id`='$domain' limit 100"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) >= 1) { ?> + $res = mysql_query($query); + if(mysql_num_rows($res) >= 1) { ?>
-= 100) { ?> += 100) { ?> - +
:


- diff --git a/pages/account/5.php b/pages/account/5.php index 49ef4ca..efed0ab 100644 --- a/pages/account/5.php +++ b/pages/account/5.php @@ -53,15 +53,15 @@ $query .= " HAVING `timeleft` > 0 or `expire` = 0 "; $query .= " ORDER BY `modified` desc"; // echo $query."
\n"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { ?> 0) $verified = _("Valid"); diff --git a/pages/account/51.php b/pages/account/51.php index d0b8367..7273840 100644 --- a/pages/account/51.php +++ b/pages/account/51.php @@ -19,13 +19,13 @@ 0) { ?> + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { ?> 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { echo _("This UID has already been voted on."); } else { diff --git a/pages/account/52.php b/pages/account/52.php index 5042852..6c00c26 100644 --- a/pages/account/52.php +++ b/pages/account/52.php @@ -21,13 +21,13 @@ if($_SESSION['profile']['tverify'] <= 0) { } else { $uid = intval($_GET['uid']); $query = "select * from `tverify` where `id`='".intval($uid)."' and `modified`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { + $row = mysql_fetch_assoc($res); $memid = intval($row['memid']); $query2 = "select * from `tverify-vote` where `tverify`='".intval($uid)."' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $rc2 = mysqli_num_rows(mysqli_query($_SESSION['mconn'], $query2)); + $rc2 = mysql_num_rows(mysql_query($query2)); if($rc2 > 0) { showheader(_("My CAcert.org Account!")); echo _("You have already voted on this request."); @@ -36,9 +36,9 @@ if($_SESSION['profile']['tverify'] <= 0) { } $query = "select sum(`points`) as `points` from `notary` where `to`='".intval($memid)."' and `deleted` = 0"; - $notary = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], $query)); + $notary = mysql_fetch_assoc(mysql_query($query)); $query = "select * from `users` where `id`='".intval($memid)."'"; - $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], $query)); + $user = mysql_fetch_assoc(mysql_query($query)); $tobe = 50 - $notary['points']; if($row['URL'] != '' && $row['photoid'] != '') { $tobe = 150 - $notary['points']; @@ -74,8 +74,8 @@ if($_SESSION['profile']['tverify'] <= 0) { 0) { + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { echo _("This UID has already been voted on.")."
"; } else { if($uid) echo _("Unable to locate a valid request for that UID.")."
"; @@ -83,13 +83,13 @@ if($_SESSION['profile']['tverify'] <= 0) { // Search for open requests: $query = "select * from `tverify` where `modified`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) > 0) { + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { echo "
"._("The following requests are still open:")."
    "; - while($row = mysqli_fetch_assoc($res)) { + while($row = mysql_fetch_assoc($res)) { $uid=intval($row['id']); $query3 = "select * from `tverify-vote` where `tverify`='".intval($uid)."' and `memid`='".intval($_SESSION['profile']['id'])."'"; - $rc3 = mysqli_num_rows(mysqli_query($_SESSION['mconn'], $query3)); + $rc3 = mysql_num_rows(mysql_query($query3)); if($rc3 <= 0) { echo "
  • ".intval($row['id'])."
  • \n"; diff --git a/pages/account/53.php b/pages/account/53.php index 82509f6..cc9e2d6 100644 --- a/pages/account/53.php +++ b/pages/account/53.php @@ -16,7 +16,7 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA */ ?> 0) { - $reg = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `regions` where `id`='$regid'")); + $reg = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'")); $display = "
      \n
    • \n". "".sanitizeHTML($reg['name'])." - "._("Add")."\n". $display; @@ -38,7 +38,7 @@ if($ccid > 0) { - $cnt = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `countries` where `id`='$ccid'")); + $cnt = mysql_fetch_assoc(mysql_query("select * from `countries` where `id`='$ccid'")); $display = "
        \n
      • \n". "".sanitizeHTML($cnt['name'])." - "._("Add")."\n". $display; @@ -51,16 +51,16 @@ { echo "
          \n"; $query = "select * from `countries` order by `name`"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) echo "
        • ".sanitizeHTML($row['name'])."
        • \n"; echo "
        \n
      • \n
      \n
      \n"; } elseif($regid <= 0) { echo "
        \n"; $query = "select * from `regions` where `ccid`='$ccid' order by `name`"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { echo "
      • ( "._("edit")." |"; echo " ( "._("move")." |"; echo " "._("aliases")." |"; @@ -89,7 +89,7 @@ echo "
      \n
    • \n
    \n\n
\n
\n"; $st="";$prev="";$end="";$next=""; - $rc = mysqli_num_rows(mysqli_query($_SESSION['mconn'], "select * from `locations` where `regid`='$regid'")); + $rc = mysql_num_rows(mysql_query("select * from `locations` where `regid`='$regid'")); if($start > 0) { $prev = $start - $limit; diff --git a/pages/account/54.php b/pages/account/54.php index 714de6c..753b4af 100644 --- a/pages/account/54.php +++ b/pages/account/54.php @@ -19,7 +19,7 @@ $ccid = array_key_exists('ccid',$_REQUEST)?intval($_REQUEST['ccid']):0; $regid = array_key_exists('regid',$_REQUEST)?intval($_REQUEST['regid']):0; $locid = array_key_exists('locid',$_REQUEST)?intval($_REQUEST['locid']):0; - $name = array_key_exists('name',$_REQUEST)?mysqli_real_escape_string($_SESSION['mconn'],$_REQUEST['name']):""; + $name = array_key_exists('name',$_REQUEST)?mysql_escape_string($_REQUEST['name']):""; if($ccid > 0 && $_REQUEST['action'] == "add") { ?> @@ -41,7 +41,7 @@ 0 && $_REQUEST['action'] == "edit") { $query = "select * from `regions` where `id`='$regid' order by `name`"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], $query)); + $row = mysql_fetch_assoc(mysql_query($query)); $name = $row['name']; ?> @@ -89,7 +89,7 @@ 0 && $_REQUEST['action'] == "edit") { $query = "select * from `locations` where `id`='$locid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], $query)); + $row = mysql_fetch_assoc(mysql_query($query)); if($name == "") $name = $row['name']; @@ -125,8 +125,8 @@ 0 && $_REQUEST['action'] == "aliases") { $query = "select * from `localias` where `locid`='".intval($locid)."'"; - $res = mysqli_query($_SESSION['mconn'], $query); - $rc = mysqli_num_rows($res); + $res = mysql_query($query); + $rc = mysql_num_rows($res); ?>
@@ -143,7 +143,7 @@ @@ -169,7 +169,7 @@ document.getElementById("display1").style.display = "none"; 0 && $_REQUEST['action'] == "move") { $query = "select * from `locations` where `id`='$locid'"; - $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], $query)); + $row = mysql_fetch_assoc(mysql_query($query)); $newreg = $_REQUEST['newreg'] = $row['regid']; ?> @@ -186,8 +186,8 @@ document.getElementById("display1").style.display = "none";
@@ -61,10 +61,10 @@ " WHERE `CP`.`variant_id`=`CV`.`id` AND `CV`.`type_id`=`CT`.`id` AND `CP`.`user_id` ='".intval($user_id)."'". " ORDER BY `CP`.`pass_date`"; - $res = mysqli_query($_SESSION['mconn'], $query); + $res = mysql_query($query); $HaveTest=0; - while($row = mysqli_fetch_array($res, MYSQL_NUM)) + while($row = mysql_fetch_array($res, MYSQL_NUM)) { if ($row[1] == "Assurer Challenge") { $HaveTest=1; @@ -99,11 +99,11 @@ AND `n`.`deleted` = 0 GROUP BY `u`.`id`, `u`.`assurer` '; - $res = mysqli_query($_SESSION['mconn'], $query); + $res = mysql_query($query); if (!$res) { print ''."\n"; } else { - $row = mysqli_fetch_array($res, MYSQL_NUM); + $row = mysql_fetch_array($res, MYSQL_NUM); if ($HaveTest && ($row[2]>=100)) { if (!$row[1]) { // This should not happen... diff --git a/pages/account/56.php b/pages/account/56.php index 796fa34..cabe8e0 100644 --- a/pages/account/56.php +++ b/pages/account/56.php @@ -25,8 +25,8 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA diff --git a/pages/account/57.php b/pages/account/57.php index a5c721c..9db7ccf 100644 --- a/pages/account/57.php +++ b/pages/account/57.php @@ -25,12 +25,12 @@ } else { $user_id = intval($_REQUEST['userid']); $query = "select * from `users` where `id`='$user_id' and `users`.`deleted`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { echo _("I'm sorry, the user you were looking for seems to have disappeared! Bad things are afoot!"); } else { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); ?>
'._('Internal Error').'
diff --git a/pages/account/58.php b/pages/account/58.php index d6bebf6..af26b70 100644 --- a/pages/account/58.php +++ b/pages/account/58.php @@ -21,19 +21,19 @@ if ($_SESSION['profile']['admin'] != 1 || !array_key_exists('userid',$_REQUEST) } else { $user_id = intval($_REQUEST['userid']); $query = "select `users`.`fname`, `users`.`mname`, `users`.`lname` from `users` where `id`='$user_id' and `users`.`deleted`=0"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) != 1){ + $res = mysql_query($query); + if(mysql_num_rows($res) != 1){ echo _("I'm sorry, the user you were looking for seems to have disappeared! Bad things are afoot!"); } else { - if ($row = mysqli_fetch_assoc($res)){ + if ($row = mysql_fetch_assoc($res)){ $username=sanitizeHTML($row['fname']).' '.sanitizeHTML($row['mname']).' '.sanitizeHTML($row['lname']); $query = "select `orginfo`.`o`, `org`.`masteracc` FROM `orginfo`, `org` WHERE `orginfo`.`id` = `org`.`orgid` AND `org`.`memid`='$user_id' order by `orginfo`.`o`"; - $res1 = mysqli_query($_SESSION['mconn'], $query);?> + $res1 = mysql_query($query);?>
+ if (mysql_num_rows($res1) <= 0) {?> @@ -45,7 +45,7 @@ if ($_SESSION['profile']['admin'] != 1 || !array_key_exists('userid',$_REQUEST) + while($drow = mysql_fetch_assoc($res1)){?> diff --git a/pages/account/59.php b/pages/account/59.php index 9052cb3..1c73ae5 100644 --- a/pages/account/59.php +++ b/pages/account/59.php @@ -21,13 +21,13 @@ include_once($_SESSION['_config']['filepath']."/includes/notary.inc.php"); $userid = intval($_REQUEST['userid']); $res = get_user_data($userid); -if (mysqli_num_rows($res) <= 0) +if (mysql_num_rows($res) <= 0) { echo _("I'm sorry, the user you were looking for seems to have disappeared! Bad things are afoot!"); exit; } -$user = mysqli_fetch_assoc($res); +$user = mysql_fetch_assoc($res); $fname = $user['fname']; $mname = $user['mname']; @@ -159,9 +159,9 @@ $dres = get_email_addresses($userid,'',1); 0) { +if (mysql_num_rows($dres) > 0) { output_log_email_header(); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_log_email($drow,$email); } @@ -185,9 +185,9 @@ $dres = get_domains($userid, 1); 0) { +if (mysql_num_rows($dres) > 0) { output_log_domains_header(); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_log_domains($drow); } @@ -211,9 +211,9 @@ $dres = get_training_results($userid); 0) { +if (mysql_num_rows($dres) > 0) { output_log_training_header(); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_log_training($drow); } @@ -237,9 +237,9 @@ $dres = get_user_agreements($userid); 0) { +if (mysql_num_rows($dres) > 0) { output_log_agreement_header(); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_log_agreement($drow); } @@ -267,9 +267,9 @@ if (1 == $support) { 0) { +if (mysql_num_rows($dres) > 0) { output_client_cert_header($support); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_client_cert($drow,$support); } @@ -297,9 +297,9 @@ if (1 == $support) { 0) { +if (mysql_num_rows($dres) > 0) { output_server_certs_header($support); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_server_certs($drow,$support); } @@ -327,9 +327,9 @@ if (1 == $support) { 0) { +if (mysql_num_rows($dres) > 0) { output_gpg_certs_header($support); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_gpg_certs($drow, $support); } @@ -362,9 +362,9 @@ if (1 == $support) { 0) { +if (mysql_num_rows($dres) > 0) { output_log_se_header($support); - while ($drow = mysqli_fetch_assoc($dres)) + while ($drow = mysql_fetch_assoc($dres)) { output_log_se($drow,$support); } diff --git a/pages/account/6.php b/pages/account/6.php index d16ef84..de8d1a3 100644 --- a/pages/account/6.php +++ b/pages/account/6.php @@ -39,14 +39,14 @@ $query = "select UNIX_TIMESTAMP(`emailcerts`.`created`) as `created`, where `emailcerts`.`id`='$certid' and `emailcerts`.`memid`='".intval($_SESSION['profile']['id'])."'"; -$res = mysqli_query($_SESSION['mconn'], $query); -if(mysqli_num_rows($res) <= 0) { +$res = mysql_query($query); +if(mysql_num_rows($res) <= 0) { showheader(_("My CAcert.org Account!")); echo _("No such certificate attached to your account."); showfooter(); exit; } -$row = mysqli_fetch_assoc($res); +$row = mysql_fetch_assoc($res); if (array_key_exists('format', $_REQUEST)) { diff --git a/pages/account/9.php b/pages/account/9.php index 8d207ee..1be45f5 100644 --- a/pages/account/9.php +++ b/pages/account/9.php @@ -27,15 +27,15 @@ 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $end = date("Y-m-d H:i:s", mktime(date("H"), date("i"), date("s"), date("m")+$row['months'], date("d"), date("Y"))); $query = "update `advertising` set `expires`='$end', `active`=1, `approvedby`='".$_SESSION['profile']['id']."' where `id`='$approve'"; - mysqli_query($_SESSION['mconn'],$query); + mysql_query($query); echo "

The ad was approved and is now active.

\n"; } } @@ -38,13 +38,13 @@ { $deactive = intval($_REQUEST['deactive']); $query = "select * from `advertising` where `id`='$deactive'"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) > 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $end = date("Y-m-d H:i:s", mktime(date("H"), date("i"), date("s"), date("m")+$row['months'], date("d"), date("Y"))); $query = "update `advertising` set `active`=0 where `id`='$deactive'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); echo "

The ad was deactivated and is now inactive.

\n"; } } @@ -69,8 +69,8 @@ $query .= "and `active`=1 having `timeleft` > 0 "; $query .= "order by `id` desc"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { if($row['expires'] == "0000-00-00 00:00:00") $status = "Pending"; diff --git a/pages/gpg/2.php b/pages/gpg/2.php index 7990236..84e11d2 100644 --- a/pages/gpg/2.php +++ b/pages/gpg/2.php @@ -33,15 +33,15 @@ `expire`, `id`, `level`, `email`,`keyid`,`description` from `gpg` where `memid`='".intval($_SESSION['profile']['id'])."' ORDER BY `issued` desc"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { ?> 0) diff --git a/pages/gpg/3.php b/pages/gpg/3.php index d33242f..d9f54fb 100644 --- a/pages/gpg/3.php +++ b/pages/gpg/3.php @@ -18,14 +18,14 @@

diff --git a/pages/wot/1.php b/pages/wot/1.php
index 2a890b3..9047f27 100644
--- a/pages/wot/1.php
+++ b/pages/wot/1.php
@@ -16,7 +16,7 @@
     Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301  USA
 */
 
-	$res=mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select sum(acount) as summe from countries"));
+	$res=mysql_fetch_assoc(mysql_query("select sum(acount) as summe from countries"));
 	$total1 =$res['summe'];
 
 	$locid=array_key_exists('locid',$_REQUEST)?intval($_REQUEST['locid']):0;
@@ -29,7 +29,7 @@
 	$display = "";
 	if($locid > 0)
 	{
-		$loc = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `locations` where `id`='".$locid."'"));
+		$loc = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='".$locid."'"));
 		$display = "
    \n
  • \n". "".$loc['name']." ("._("Listed").": ".$loc['acount'].")\n". $display; @@ -38,7 +38,7 @@ if($regid > 0) { - $reg = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `regions` where `id`='".$regid."'")); + $reg = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='".$regid."'")); $display = "
      \n
    • \n". "".$reg['name']." ("._("Listed").": ".$reg['acount'].")\n". $display; @@ -47,7 +47,7 @@ if($ccid > 0) { - $cnt = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `countries` where `id`='".$ccid."'")); + $cnt = mysql_fetch_assoc(mysql_query("select * from `countries` where `id`='".$ccid."'")); $display = "
        \n
      • \n". "".$cnt['name']." ("._("Listed").": ".$cnt['acount'].")\n". $display; @@ -60,8 +60,8 @@ { echo "
          \n"; $query = "select * from countries where acount>0 order by `name`"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { echo "
        • ".$row['name']." ("._("Listed").": ".$row['acount'].")
        • \n"; } @@ -69,8 +69,8 @@ } elseif($ccid > 0 && $regid <= 0 && $locid <= 0) { echo "
            \n"; $query = "select * from regions where ccid='".$ccid."' and acount>0 order by `name`"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { echo "
          • ".$row['name']." ("._("Listed").": ".$row['acount'].")
          • \n"; } @@ -78,8 +78,8 @@ } elseif($regid > 0 && $locid <= 0) { echo "
              \n"; $query = "select * from locations where regid='".$regid."' and acount>0 order by `name`"; - $res = mysqli_query($_SESSION['mconn'], $query); - while($row = mysqli_fetch_assoc($res)) + $res = mysql_query($query); + while($row = mysql_fetch_assoc($res)) { echo "
            • ".$row['name']." ("._("Listed").": ".$row['acount'].")
            • \n"; } @@ -93,8 +93,8 @@ `ccid`='".$ccid."' and `regid`='".$regid."' and `locid`='".$locid."' and `users`.`id`=`notary`.`to` and `notary`.`deleted`=0 group by `notary`.`to` HAVING SUM(`points`) >= 100 order by `points` desc"; - $list = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($list) > 0) + $list = mysql_query($query); + if(mysql_num_rows($list) > 0) { ?>
@@ -106,7 +106,7 @@ - + diff --git a/pages/wot/10.php b/pages/wot/10.php index 7f3bd57..b5e146c 100644 --- a/pages/wot/10.php +++ b/pages/wot/10.php @@ -28,8 +28,8 @@ $query = "SELECT `users`. *, count(*) AS `list` FROM `users`, `notary` WHERE `users`.`id` = `notary`.`from` AND `notary`.`from` != `notary`.`to` AND `from`='".intval($_SESSION['profile']['id'])."' GROUP BY `notary`.`from`"; - $res = mysqli_query($_SESSION['mconn'], $query); - $row = mysqli_fetch_assoc($res); + $res = mysql_query($query); + $row = mysql_fetch_assoc($res); $rc = intval($row['list']); /* $query = "SELECT `users`. *, count(*) AS `list` FROM `users`, `notary` @@ -40,7 +40,7 @@ inner join `notary` on `users`.`id` = `notary`.`from` GROUP BY `notary`.`from` HAVING count(*) > '$rc'"; - $rank = mysqli_num_rows(mysqli_query($_SESSION['mconn'], $query)) + 1; + $rank = mysql_num_rows(mysql_query($query)) + 1; ?> @@ -65,10 +65,10 @@ @@ -115,10 +115,10 @@ if ($thawte)
.
@@ -117,7 +117,7 @@ document.f.location.focus(); - 35) diff --git a/pages/wot/13.php b/pages/wot/13.php index 7afb6c5..eac7e18 100644 --- a/pages/wot/13.php +++ b/pages/wot/13.php @@ -21,40 +21,40 @@ if(array_key_exists('location',$_REQUEST) && $_REQUEST['location'] != "") { { $bits = explode(",", $_REQUEST['location']); - $loc = trim(mysqli_real_escape_string($_SESSION['mconn'], $bits['0'])); - $reg = ''; if(array_key_exists('1',$bits)) $reg=trim(mysqli_real_escape_string($_SESSION['mconn'], $bits['1'])); - $ccname = ''; if(array_key_exists('2',$bits)) $ccname=trim(mysqli_real_escape_string($_SESSION['mconn'], $bits['2'])); + $loc = trim(mysql_escape_string($bits['0'])); + $reg = ''; if(array_key_exists('1',$bits)) $reg=trim(mysql_escape_string($bits['1'])); + $ccname = ''; if(array_key_exists('2',$bits)) $ccname=trim(mysql_escape_string($bits['2'])); $query = "select `locations`.`id` as `locid` from `locations`, `regions`, `countries` where `locations`.`name` like '$loc%' and `regions`.`name` like '$reg%' and `countries`.`name` like '$ccname%' and `locations`.`regid`=`regions`.`id` and `locations`.`ccid`=`countries`.`id` order by `locations`.`name` limit 1"; - $res = mysqli_query($_SESSION['mconn'], $query); - if($reg != "" && $ccname == "" && mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if($reg != "" && $ccname == "" && mysql_num_rows($res) <= 0) { $query = "select `locations`.`id` as `locid` from `locations`, `regions`, `countries` where `locations`.`name` like '$loc%' and `countries`.`name` like '$reg%' and `locations`.`regid`=`regions`.`id` and `locations`.`ccid`=`countries`.`id` order by `locations`.`name` limit 1"; - $res = mysqli_query($_SESSION['mconn'], $query); + $res = mysql_query($query); } - if(mysqli_num_rows($res) <= 0) + if(mysql_num_rows($res) <= 0) die("Unable to find suitable location"); - $row = mysqli_fetch_assoc($res); + $row = mysql_fetch_assoc($res); $_REQUEST['location'] = $row['locid']; } $locid = intval($_REQUEST['location']); $query = "select * from `locations` where `id`='$locid'"; - $res = mysqli_query($_SESSION['mconn'], $query); - if(mysqli_num_rows($res) > 0) + $res = mysql_query($query); + if(mysql_num_rows($res) > 0) { - $loc = mysqli_fetch_assoc($res); + $loc = mysql_fetch_assoc($res); $_SESSION['profile']['ccid'] = $loc['ccid']; $_SESSION['profile']['regid'] = $loc['regid']; $_SESSION['profile']['locid'] = $loc['id']; $query = "update `users` set `locid`='$loc[id]', `regid`='$loc[regid]', `ccid`='$loc[ccid]' where `id`='".$_SESSION['profile']['id']."'"; - mysqli_query($_SESSION['mconn'], $query); + mysql_query($query); echo "

"._("Your location has been updated")."

\n"; } else { echo "

"._("I was unable to match your location with places in my database.")."

\n"; @@ -62,14 +62,14 @@ if(array_key_exists('location',$_REQUEST) && $_REQUEST['location'] != "") { } $query = "select `name` from `locations` where `id`='".$_SESSION['profile']['locid']."'"; - $res = mysqli_query($_SESSION['mconn'], $query); - $loc = mysqli_fetch_assoc($res); + $res = mysql_query($query); + $loc = mysql_fetch_assoc($res); $query = "select `name` from `regions` where `id`='".$_SESSION['profile']['regid']."'"; - $res = mysqli_query($_SESSION['mconn'], $query); - $reg = mysqli_fetch_assoc($res); + $res = mysql_query($query); + $reg = mysql_fetch_assoc($res); $query = "select `name` from `countries` where `id`='".$_SESSION['profile']['ccid']."'"; - $res = mysqli_query($_SESSION['mconn'], $query); - $cc = mysqli_fetch_assoc($res); + $res = mysql_query($query); + $cc = mysql_fetch_assoc($res); ?>