diff --git a/includes/account.php b/includes/account.php
index d14e27d..6dacf2d 100644
--- a/includes/account.php
+++ b/includes/account.php
@@ -120,7 +120,7 @@ function buildSubjectFromSession() {
showfooter();
exit;
}
- if(trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newemail']))) == "")
+ if(trim(mysql_real_escape_string(stripslashes($_REQUEST['newemail']))) == "")
{
showheader(_("My CAcert.org Account!"));
printf(_("Not a valid email address. Can't continue."));
@@ -128,7 +128,7 @@ function buildSubjectFromSession() {
exit;
}
$oldid=0;
- $_REQUEST['email'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newemail'])));
+ $_REQUEST['email'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['newemail'])));
if(check_email_exists($_REQUEST['email'])==true)
{
showheader(_("My CAcert.org Account!"));
@@ -152,8 +152,8 @@ function buildSubjectFromSession() {
}
$hash = make_hash();
$query = "insert into `email` set `email`='".$_REQUEST['email']."',`memid`='".intval($_SESSION['profile']['id'])."',`created`=NOW(),`hash`='$hash'";
- mysqli_query($_SESSION['mconn'],$query);
- $emailid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $emailid = mysql_insert_id();
$body = _("Below is the link you need to open to verify your email address. Once your address is verified you will be able to start issuing certificates to your heart's content!")."\n\n";
$body .= "http://".$_SESSION['_config']['normalhostname']."/verify.php?type=email&emailid=$emailid&hash=$hash\n\n";
@@ -172,15 +172,15 @@ function buildSubjectFromSession() {
$id = 2;
$emailid = intval($_REQUEST['emailid']);
$query = "select * from `email` where `id`='$emailid' and `memid`='".intval($_SESSION['profile']['id'])."' and `hash` = '' and `deleted`=0";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
showheader(_("Error!"));
echo _("You currently don't have access to the email address you selected, or you haven't verified it yet.");
showfooter();
exit;
}
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
$body = sprintf(_("Hi %s,"),$_SESSION['profile']['fname'])."\n\n";
$body .= _("You are receiving this email because you or someone else ".
"has changed the default email on your account.")."\n\n";
@@ -191,8 +191,8 @@ function buildSubjectFromSession() {
"support@cacert.org", "", "", "CAcert Support");
$_SESSION['profile']['email'] = $row['email'];
- $query = "update `users` set `email`='".mysqli_real_escape_string($_SESSION['mconn'], $row['email'])."' where `id`='".intval($_SESSION['profile']['id'])."'";
- mysqli_query($_SESSION['mconn'],$query);
+ $query = "update `users` set `email`='".mysql_real_escape_string($row['email'])."' where `id`='".intval($_SESSION['profile']['id'])."'";
+ mysql_query($query);
showheader(_("My CAcert.org Account!"));
printf(_("Your default email address has been updated to '%s'."), sanitizeHTML($row['email']));
showfooter();
@@ -216,11 +216,11 @@ function buildSubjectFromSession() {
}
$id = intval($id);
$query = "select * from `email` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."' and
- `email`!='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['profile']['email'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) > 0)
+ `email`!='".mysql_real_escape_string($_SESSION['profile']['email'])."'";
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) > 0)
{
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
echo $row['email']."
\n";
account_email_delete($row['id']);
$delcount++;
@@ -326,10 +326,10 @@ function buildSubjectFromSession() {
if(is_array($_SESSION['_config']['addid']))
foreach($_SESSION['_config']['addid'] as $id)
{
- $res = mysqli_query($_SESSION['mconn'],"select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'");
- if(mysqli_num_rows($res) > 0)
+ $res = mysql_query("select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'");
+ if(mysql_num_rows($res) > 0)
{
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if(!$emails)
$defaultemail = $row['email'];
$emails .= "$count.emailAddress = ".$row['email']."\n";
@@ -345,7 +345,7 @@ function buildSubjectFromSession() {
showfooter();
exit;
}
- $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'"));
+ $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'"));
if($_SESSION['_config']['SSO'] == 1)
$emails .= "$count.emailAddress = ".$user['uniqueID']."\n";
@@ -389,13 +389,13 @@ function buildSubjectFromSession() {
`codesign`='".intval($_SESSION['_config']['codesign'])."',
`disablelogin`='".($_SESSION['_config']['disablelogin']?1:0)."',
`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
- mysqli_query($_SESSION['mconn'],$query);
- $emailid = mysqli_insert_id($_SESSION['mconn']);
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
+ mysql_query($query);
+ $emailid = mysql_insert_id();
if(is_array($addys))
foreach($addys as $addy)
- mysqli_query($_SESSION['mconn'],"insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='$addy'");
+ mysql_query("insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='$addy'");
$CSRname=generatecertpath("csr","client",$emailid);
$fp = fopen($CSRname, "w");
fputs($fp, $emails);
@@ -411,7 +411,7 @@ function buildSubjectFromSession() {
showfooter();
exit;
}
- mysqli_query($_SESSION['mconn'],"update `emailcerts` set `csr_name`='$CSRname' where `id`='".intval($emailid)."'");
+ mysql_query("update `emailcerts` set `csr_name`='$CSRname' where `id`='".intval($emailid)."'");
} else if($_REQUEST['keytype'] == "MS" || $_REQUEST['keytype'] == "VI") {
if($csr == "")
$csr = "-----BEGIN CERTIFICATE REQUEST-----\n".clean_csr($_REQUEST['CSR'])."\n-----END CERTIFICATE REQUEST-----\n";
@@ -434,7 +434,7 @@ function buildSubjectFromSession() {
$defaultemail = "";
$csrsubject="";
- $user = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'"));
+ $user = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_SESSION['profile']['id'])."'"));
if(strlen($user['mname']) == 1)
$user['mname'] .= '.';
if($_SESSION['_config']['incname'] <= 0 || $_SESSION['_config']['incname'] > 4)
@@ -450,10 +450,10 @@ function buildSubjectFromSession() {
if(is_array($_SESSION['_config']['addid']))
foreach($_SESSION['_config']['addid'] as $id)
{
- $res = mysqli_query($_SESSION['mconn'],"select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'");
- if(mysqli_num_rows($res) > 0)
+ $res = mysql_query("select * from `email` where `memid`='".intval($_SESSION['profile']['id'])."' and `id`='".intval($id)."'");
+ if(mysql_num_rows($res) > 0)
{
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if($defaultemail == "")
$defaultemail = $row['email'];
$csrsubject .= "/emailAddress=".$row['email'];
@@ -490,27 +490,27 @@ function buildSubjectFromSession() {
`keytype`='".sanitizeHTML($_REQUEST['keytype'])."',
`memid`='".intval($_SESSION['profile']['id'])."',
`created`=FROM_UNIXTIME(UNIX_TIMESTAMP()),
- `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."',
+ `subject`='".mysql_real_escape_string($csrsubject)."',
`codesign`='".intval($_SESSION['_config']['codesign'])."',
`disablelogin`='".($_SESSION['_config']['disablelogin']?1:0)."',
`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
- mysqli_query($_SESSION['mconn'],$query);
- $emailid = mysqli_insert_id($_SESSION['mconn']);
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
+ mysql_query($query);
+ $emailid = mysql_insert_id();
if(is_array($addys))
foreach($addys as $addy)
- mysqli_query($_SESSION['mconn'],"insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='".mysqli_real_escape_string($_SESSION['mconn'], $addy)."'");
+ mysql_query("insert into `emaillink` set `emailcertsid`='$emailid', `emailid`='".mysql_real_escape_string($addy)."'");
$CSRname=generatecertpath("csr","client",$emailid);
$fp = fopen($CSRname, "w");
fputs($fp, $csr);
fclose($fp);
- mysqli_query($_SESSION['mconn'],"update `emailcerts` set `csr_name`='$CSRname' where `id`='$emailid'");
+ mysql_query("update `emailcerts` set `csr_name`='$CSRname' where `id`='$emailid'");
}
waitForResult("emailcerts", $emailid, 4);
$query = "select * from `emailcerts` where `id`='$emailid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
$id = 4;
showheader(_("My CAcert.org Account!"));
@@ -547,12 +547,12 @@ function buildSubjectFromSession() {
}
$newdom = trim(escapeshellarg($newdomain));
- $newdomain = mysqli_real_escape_string($_SESSION['mconn'], trim($newdomain));
+ $newdomain = mysql_real_escape_string(trim($newdomain));
- $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain`='$newdomain'");
+ $res1 = mysql_query("select * from `orgdomains` where `domain`='$newdomain'");
$query = "select * from `domains` where `domain`='$newdomain' and `deleted`=0";
- $res2 = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res1) > 0 || mysqli_num_rows($res2))
+ $res2 = mysql_query($query);
+ if(mysql_num_rows($res1) > 0 || mysql_num_rows($res2))
{
$oldid=0;
$id = 7;
@@ -579,7 +579,7 @@ function buildSubjectFromSession() {
$bits = explode(":", $line, 2);
$line = trim($bits[1]);
if(!in_array($line, $addy) && $line != "")
- $addy[] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($line)));
+ $addy[] = trim(mysql_real_escape_string(stripslashes($line)));
}
} else {
if(is_array($adds))
@@ -597,7 +597,7 @@ function buildSubjectFromSession() {
$line = $bit;
}
if(!in_array($line, $addy) && $line != "")
- $addy[] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($line)));
+ $addy[] = trim(mysql_real_escape_string(stripslashes($line)));
}
}
@@ -606,7 +606,7 @@ function buildSubjectFromSession() {
if(!in_array($sub, $addy))
$addy[] = $sub;
$_SESSION['_config']['addy'] = $addy;
- $_SESSION['_config']['domain'] = mysqli_real_escape_string($_SESSION['mconn'], $newdomain);
+ $_SESSION['_config']['domain'] = mysql_real_escape_string($newdomain);
}
if($process != "" && $oldid == 8)
@@ -615,7 +615,7 @@ function buildSubjectFromSession() {
$oldid=0;
$id = 8;
- $authaddy = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['authaddy'])));
+ $authaddy = trim(mysql_real_escape_string(stripslashes($_REQUEST['authaddy'])));
if($authaddy == "" || !is_array($_SESSION['_config']['addy']))
{
@@ -633,9 +633,9 @@ function buildSubjectFromSession() {
exit;
}
- $query = "select * from `domains` where `domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['domain'])."' and `deleted`=0";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) > 0)
+ $query = "select * from `domains` where `domain`='".mysql_real_escape_string($_SESSION['_config']['domain'])."' and `deleted`=0";
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) > 0)
{
showheader(_("My CAcert.org Account!"));
printf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($_SESSION['_config']['domain']));
@@ -659,10 +659,10 @@ function buildSubjectFromSession() {
}
$hash = make_hash();
- $query = "insert into `domains` set `domain`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['domain'])."',
+ $query = "insert into `domains` set `domain`='".mysql_real_escape_string($_SESSION['_config']['domain'])."',
`memid`='".intval($_SESSION['profile']['id'])."',`created`=NOW(),`hash`='$hash'";
- mysqli_query($_SESSION['mconn'],$query);
- $domainid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $domainid = mysql_insert_id();
$body = sprintf(_("Below is the link you need to open to verify your domain '%s'. Once your address is verified you will be able to start issuing certificates to your heart's content!"),$_SESSION['_config']['domain'])."\n\n";
$body .= "http://".$_SESSION['_config']['normalhostname']."/verify.php?type=domain&domainid=$domainid&hash=$hash\n\n";
@@ -689,10 +689,10 @@ function buildSubjectFromSession() {
{
$id = intval($id);
$query = "select * from `domains` where `id`='$id' and `memid`='".intval($_SESSION['profile']['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) > 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) > 0)
{
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
echo $row['domain']."
\n";
account_domain_delete($row['id']);
}
@@ -810,20 +810,20 @@ function buildSubjectFromSession() {
if(array_key_exists('0',$_SESSION['_config']['rowid']) && $_SESSION['_config']['rowid']['0'] > 0)
{
$query = "insert into `domaincerts` set
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rows']['0'])."',
- `domid`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rowid']['0'])."',
- `created`=NOW(),`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $subject)."',
- `rootcert`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+ `CN`='".mysql_real_escape_string($_SESSION['_config']['rows']['0'])."',
+ `domid`='".mysql_real_escape_string($_SESSION['_config']['rowid']['0'])."',
+ `created`=NOW(),`subject`='".mysql_real_escape_string($subject)."',
+ `rootcert`='".mysql_real_escape_string($_SESSION['_config']['rootcert'])."',
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
} elseif(array_key_exists('0',$_SESSION['_config']['altid']) && $_SESSION['_config']['altid']['0'] > 0) {
$query = "insert into `domaincerts` set
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altrows']['0'])."',
- `domid`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altid']['0'])."',
- `created`=NOW(),`subject`='".mysqli_real_escape_string($_SESSION['mconn'], $subject)."',
- `rootcert`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+ `CN`='".mysql_real_escape_string($_SESSION['_config']['altrows']['0'])."',
+ `domid`='".mysql_real_escape_string($_SESSION['_config']['altid']['0'])."',
+ `created`=NOW(),`subject`='".mysql_real_escape_string($subject)."',
+ `rootcert`='".mysql_real_escape_string($_SESSION['_config']['rootcert'])."',
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
} else {
showheader(_("My CAcert.org Account!"));
echo _("Domain not verified.");
@@ -831,24 +831,24 @@ function buildSubjectFromSession() {
exit;
}
- mysqli_query($_SESSION['mconn'],$query);
- $CSRid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $CSRid = mysql_insert_id();
if(is_array($_SESSION['_config']['rowid']))
foreach($_SESSION['_config']['rowid'] as $dom)
- mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='$dom'");
+ mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='$dom'");
if(is_array($_SESSION['_config']['altid']))
foreach($_SESSION['_config']['altid'] as $dom)
- mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='$dom'");
+ mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='$dom'");
$CSRname=generatecertpath("csr","server",$CSRid);
rename($_SESSION['_config']['tmpfname'], $CSRname);
chmod($CSRname,0644);
- mysqli_query($_SESSION['mconn'],"update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
+ mysql_query("update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
waitForResult("domaincerts", $CSRid, 11);
$query = "select * from `domaincerts` where `id`='$CSRid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
$id = 11;
showheader(_("My CAcert.org Account!"));
@@ -878,14 +878,14 @@ function buildSubjectFromSession() {
where `domaincerts`.`id`='$id' and
`domaincerts`.`domid`=`domains`.`id` and
`domains`.`memid`='".intval($_SESSION['profile']['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id);
continue;
}
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if (($weakKey = checkWeakKeyX509(file_get_contents(
$row['crt_name']))) !== "")
@@ -894,20 +894,20 @@ function buildSubjectFromSession() {
continue;
}
- mysqli_query($_SESSION['mconn'],"update `domaincerts` set `renewed`='1' where `id`='$id'");
+ mysql_query("update `domaincerts` set `renewed`='1' where `id`='$id'");
$query = "insert into `domaincerts` set
`domid`='".intval($row['domid'])."',
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."',
- `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."',".
+ `CN`='".mysql_real_escape_string($row['CN'])."',
+ `subject`='".mysql_real_escape_string($row['subject'])."',".
//`csr_name`='".$row['csr_name']."', // RACE CONDITION
- "`created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."',
+ "`created`='".mysql_real_escape_string($row['created'])."',
`modified`=NOW(),
`rootcert`='".intval($row['rootcert'])."',
`type`='".intval($row['type'])."',
- `pkhash`='".mysqli_real_escape_string($_SESSION['mconn'], $row['pkhash'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'";
- mysqli_query($_SESSION['mconn'],$query);
- $newid = mysqli_insert_id($_SESSION['mconn']);
+ `pkhash`='".mysql_real_escape_string($row['pkhash'])."',
+ `description`='".mysql_real_escape_string($row['description'])."'";
+ mysql_query($query);
+ $newid = mysql_insert_id();
$newfile=generatecertpath("csr","server",$newid);
copy($row['csr_name'], $newfile);
$newfile_esc = escapeshellarg($newfile);
@@ -929,18 +929,18 @@ function buildSubjectFromSession() {
}
$subject = buildSubjectFromSession();
- $subject = mysqli_real_escape_string($_SESSION['mconn'], $subject);
- mysqli_query($_SESSION['mconn'],"update `domaincerts` set `subject`='$subject',`csr_name`='$newfile' where `id`='$newid'");
+ $subject = mysql_real_escape_string($subject);
+ mysql_query("update `domaincerts` set `subject`='$subject',`csr_name`='$newfile' where `id`='$newid'");
echo _("Renewing").": ".sanitizeHTML($_SESSION['_config']['0.CN'])."
\n";
waitForResult("domaincerts", $newid,$oldid,0);
$query = "select * from `domaincerts` where `id`='$newid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", "");
} else {
- $drow = mysqli_fetch_assoc($res);
+ $drow = mysql_fetch_assoc($res);
$crt_name = escapeshellarg($drow['crt_name']);
$cert = shell_exec("/usr/bin/openssl x509 -in $crt_name");
echo "
\n$cert\n\n"; @@ -971,19 +971,19 @@ function buildSubjectFromSession() { where `domaincerts`.`id`='$id' and `domaincerts`.`domid`=`domains`.`id` and `domains`.`memid`='".intval($_SESSION['profile']['id'])."'"; - $res = mysqli_query($_SESSION['mconn'],$query); - if(mysqli_num_rows($res) <= 0) + $res = mysql_query($query); + if(mysql_num_rows($res) <= 0) { printf(_("Invalid ID '%s' presented, can't do anything with it.")."
"; print_r($_SESSION['_config']); die;
if($_SESSION['_config']['0.CN'] == "" && $_SESSION['_config']['0.subjectAltName'] == "")
@@ -1946,7 +1946,7 @@ function buildSubjectFromSession() {
`orginfo`.`id`=`org`.`orgid` and
`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
}
- $org = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $org = mysql_fetch_assoc(mysql_query($query));
$csrsubject = "";
if($_SESSION['_config']['OU'])
@@ -1972,42 +1972,42 @@ function buildSubjectFromSession() {
if($_SESSION['_config']['rowid']['0'] > 0)
{
$query = "insert into `orgdomaincerts` set
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['rows']['0'])."',
+ `CN`='".mysql_real_escape_string($_SESSION['_config']['rows']['0'])."',
`orgid`='".intval($org['id'])."',
`created`=NOW(),
- `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."',
+ `subject`='".mysql_real_escape_string($csrsubject)."',
`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
`type`='".$type."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
} else {
$query = "insert into `orgdomaincerts` set
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['altrows']['0'])."',
+ `CN`='".mysql_real_escape_string($_SESSION['_config']['altrows']['0'])."',
`orgid`='".intval($org['id'])."',
`created`=NOW(),
- `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $csrsubject)."',
+ `subject`='".mysql_real_escape_string($csrsubject)."',
`rootcert`='".intval($_SESSION['_config']['rootcert'])."',
- `md`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['hash_alg'])."',
+ `md`='".mysql_real_escape_string($_SESSION['_config']['hash_alg'])."',
`type`='".$type."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['description'])."'";
+ `description`='".mysql_real_escape_string($_SESSION['_config']['description'])."'";
}
- mysqli_query($_SESSION['mconn'],$query);
- $CSRid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $CSRid = mysql_insert_id();
$CSRname=generatecertpath("csr","orgserver",$CSRid);
rename($_SESSION['_config']['tmpfname'], $CSRname);
chmod($CSRname,0644);
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
+ mysql_query("update `orgdomaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
if(is_array($_SESSION['_config']['rowid']))
foreach($_SESSION['_config']['rowid'] as $id)
- mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
+ mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
if(is_array($_SESSION['_config']['altid']))
foreach($_SESSION['_config']['altid'] as $id)
- mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
+ mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($id)."', `orgcertid`='$CSRid'");
waitForResult("orgdomaincerts", $CSRid,$oldid);
$query = "select * from `orgdomaincerts` where `id`='$CSRid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
showheader(_("My CAcert.org Account!"));
printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions.")." CSRid: $CSRid", "", "");
@@ -2035,14 +2035,14 @@ function buildSubjectFromSession() {
where `orgdomaincerts`.`id`='$id' and
`orgdomaincerts`.`orgid`=`org`.`orgid` and
`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id);
continue;
}
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if (($weakKey = checkWeakKeyX509(file_get_contents(
$row['crt_name']))) !== "")
@@ -2051,7 +2051,7 @@ function buildSubjectFromSession() {
continue;
}
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `renewed`='1' where `id`='$id'");
+ mysql_query("update `orgdomaincerts` set `renewed`='1' where `id`='$id'");
if($row['revoke'] > 0)
{
printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']);
@@ -2059,32 +2059,32 @@ function buildSubjectFromSession() {
}
$query = "insert into `orgdomaincerts` set
`orgid`='".intval($row['orgid'])."',
- `CN`='".mysqli_real_escape_string($_SESSION['mconn'], $row['CN'])."',
- `csr_name`='".mysqli_real_escape_string($_SESSION['mconn'], $row['csr_name'])."',
- `created`='".mysqli_real_escape_string($_SESSION['mconn'], $row['created'])."',
+ `CN`='".mysql_real_escape_string($row['CN'])."',
+ `csr_name`='".mysql_real_escape_string($row['csr_name'])."',
+ `created`='".mysql_real_escape_string($row['created'])."',
`modified`=NOW(),
- `subject`='".mysqli_real_escape_string($_SESSION['mconn'], $row['subject'])."',
+ `subject`='".mysql_real_escape_string($row['subject'])."',
`type`='".intval($row['type'])."',
`rootcert`='".intval($row['rootcert'])."',
- `description`='".mysqli_real_escape_string($_SESSION['mconn'], $row['description'])."'";
- mysqli_query($_SESSION['mconn'],$query);
- $newid = mysqli_insert_id($_SESSION['mconn']);
+ `description`='".mysql_real_escape_string($row['description'])."'";
+ mysql_query($query);
+ $newid = mysql_insert_id();
//echo "NewID: $newid
\n";
$newfile=generatecertpath("csr","orgserver",$newid);
copy($row['csr_name'], $newfile);
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `csr_name`='$newfile' where `id`='$newid'");
+ mysql_query("update `orgdomaincerts` set `csr_name`='$newfile' where `id`='$newid'");
echo _("Renewing").": ".$row['CN']."
\n";
- $res = mysqli_query($_SESSION['mconn'],"select * from `orgdomlink` where `orgcertid`='".$row['id']."'");
- while($r2 = mysqli_fetch_assoc($res))
- mysqli_query($_SESSION['mconn'],"insert into `orgdomlink` set `orgdomid`='".intval($r2['orgdomid'])."', `orgcertid`='$newid'");
+ $res = mysql_query("select * from `orgdomlink` where `orgcertid`='".$row['id']."'");
+ while($r2 = mysql_fetch_assoc($res))
+ mysql_query("insert into `orgdomlink` set `orgdomid`='".intval($r2['orgdomid'])."', `orgcertid`='$newid'");
waitForResult("orgdomaincerts", $newid,$oldid,0);
$query = "select * from `orgdomaincerts` where `id`='$newid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions.")." newid: $newid", "", "");
} else {
- $drow = mysqli_fetch_assoc($res);
+ $drow = mysql_fetch_assoc($res);
$crtname = escapeshellarg($drow['crt_name']);
$cert = shell_exec("/usr/bin/openssl x509 -in $crtname");
echo "\n$cert\n
\n";
@@ -2114,19 +2114,19 @@ function buildSubjectFromSession() {
where `orgdomaincerts`.`id`='$id' and
`orgdomaincerts`.`orgid`=`org`.`orgid` and
`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id);
continue;
}
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if($row['revoke'] > 0)
{
printf(_("It would seem '%s' has already been revoked. I'll skip this for now.")."
\n", $row['CN']);
continue;
}
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'");
+ mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='$id'");
printf(_("Certificate for '%s' with the serial no '%s' has been revoked.").'
', htmlspecialchars($row['CN']), htmlspecialchars($row['serial']));
}
@@ -2149,19 +2149,19 @@ function buildSubjectFromSession() {
where `orgdomaincerts`.`id`='$id' and
`orgdomaincerts`.`orgid`=`org`.`orgid` and
`org`.`memid`='".intval($_SESSION['profile']['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
printf(_("Invalid ID '%s' presented, can't do anything with it.")."
\n", $id);
continue;
}
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if($row['expired'] > 0)
{
printf(_("Couldn't remove the request for `%s`, request had already been processed.")."
\n", $row['CN']);
continue;
}
- mysqli_query($_SESSION['mconn'],"delete from `orgdomaincerts` where `id`='$id'");
+ mysql_query("delete from `orgdomaincerts` where `id`='$id'");
@unlink($row['csr_name']);
@unlink($row['crt_name']);
printf(_("Removed a pending request for '%s'")."
\n", $row['CN']);
@@ -2179,8 +2179,8 @@ function buildSubjectFromSession() {
if(substr($id,0,14)=="check_comment_")
{
$cid = intval(substr($id,14));
- $comment=trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comment_'.$cid])));
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `description`='$comment' where `id`='$cid'");
+ $comment=trim(mysql_real_escape_string(stripslashes($_REQUEST['comment_'.$cid])));
+ mysql_query("update `orgdomaincerts` set `description`='$comment' where `id`='$cid'");
}
}
echo(_("Certificate settings have been changed.")."
\n");
@@ -2219,18 +2219,18 @@ function buildSubjectFromSession() {
if($oldid == 24 && $process != "")
{
$id = intval($oldid);
- $_SESSION['_config']['O'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['O'])));
- $_SESSION['_config']['contact'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['contact'])));
- $_SESSION['_config']['L'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['L'])));
- $_SESSION['_config']['ST'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['ST'])));
- $_SESSION['_config']['C'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['C'])));
- $_SESSION['_config']['comments'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comments'])));
+ $_SESSION['_config']['O'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['O'])));
+ $_SESSION['_config']['contact'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['contact'])));
+ $_SESSION['_config']['L'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['L'])));
+ $_SESSION['_config']['ST'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['ST'])));
+ $_SESSION['_config']['C'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['C'])));
+ $_SESSION['_config']['comments'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['comments'])));
if($_SESSION['_config']['O'] == "" || $_SESSION['_config']['contact'] == "")
{
$_SESSION['_config']['errmsg'] = _("Organisation Name and Contact Email are required fields.");
} else {
- mysqli_query($_SESSION['mconn'],"insert into `orginfo` set `O`='".$_SESSION['_config']['O']."',
+ mysql_query("insert into `orginfo` set `O`='".$_SESSION['_config']['O']."',
`contact`='".$_SESSION['_config']['contact']."',
`L`='".$_SESSION['_config']['L']."',
`ST`='".$_SESSION['_config']['ST']."',
@@ -2247,18 +2247,18 @@ function buildSubjectFromSession() {
{
csrf_check('orgdetchange');
$id = intval($oldid);
- $_SESSION['_config']['O'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['O'])));
- $_SESSION['_config']['contact'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['contact'])));
- $_SESSION['_config']['L'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['L'])));
- $_SESSION['_config']['ST'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['ST'])));
- $_SESSION['_config']['C'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['C'])));
- $_SESSION['_config']['comments'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['comments'])));
+ $_SESSION['_config']['O'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['O'])));
+ $_SESSION['_config']['contact'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['contact'])));
+ $_SESSION['_config']['L'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['L'])));
+ $_SESSION['_config']['ST'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['ST'])));
+ $_SESSION['_config']['C'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['C'])));
+ $_SESSION['_config']['comments'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['comments'])));
if($_SESSION['_config']['O'] == "" || $_SESSION['_config']['contact'] == "")
{
$_SESSION['_config']['errmsg'] = _("Organisation Name and Contact Email are required fields.");
} else {
- mysqli_query($_SESSION['mconn'],"update `orginfo` set `O`='".$_SESSION['_config']['O']."',
+ mysql_query("update `orginfo` set `O`='".$_SESSION['_config']['O']."',
`contact`='".$_SESSION['_config']['contact']."',
`L`='".$_SESSION['_config']['L']."',
`ST`='".$_SESSION['_config']['ST']."',
@@ -2274,9 +2274,9 @@ function buildSubjectFromSession() {
if($oldid == 28 && $process != "" && array_key_exists("domainname",$_REQUEST))
{
- $domain = $_SESSION['_config']['domain'] = trim(mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['domainname'])));
- $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain`='$domain'");
- if(mysqli_num_rows($res1) > 0)
+ $domain = $_SESSION['_config']['domain'] = trim(mysql_real_escape_string(stripslashes($_REQUEST['domainname'])));
+ $res1 = mysql_query("select * from `orgdomains` where `domain`='$domain'");
+ if(mysql_num_rows($res1) > 0)
{
$_SESSION['_config']['errmsg'] = sprintf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($domain));
$id = $oldid;
@@ -2292,7 +2292,7 @@ function buildSubjectFromSession() {
if($oldid == 28 && $process != "" && array_key_exists("orgid",$_SESSION["_config"]))
{
- mysqli_query($_SESSION['mconn'],"insert into `orgdomains` set `orgid`='".intval($_SESSION['_config']['orgid'])."', `domain`='$domain'");
+ mysql_query("insert into `orgdomains` set `orgid`='".intval($_SESSION['_config']['orgid'])."', `domain`='$domain'");
showheader(_("My CAcert.org Account!"));
printf(_("'%s' has just been successfully added to the database."), sanitizeHTML($domain));
echo "
"._("Click here")." "._("to continue.");
@@ -2302,11 +2302,11 @@ function buildSubjectFromSession() {
if($oldid == 29 && $process != "")
{
- $domain = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['domainname'])));
+ $domain = mysql_real_escape_string(stripslashes(trim($_REQUEST['domainname'])));
- $res1 = mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `domain` like '$domain' and `id`!='".intval($domid)."'");
- $res2 = mysqli_query($_SESSION['mconn'],"select * from `domains` where `domain` like '$domain' and `deleted`=0");
- if(mysqli_num_rows($res1) > 0 || mysqli_num_rows($res2) > 0)
+ $res1 = mysql_query("select * from `orgdomains` where `domain` like '$domain' and `id`!='".intval($domid)."'");
+ $res2 = mysql_query("select * from `domains` where `domain` like '$domain' and `deleted`=0");
+ if(mysql_num_rows($res1) > 0 || mysql_num_rows($res2) > 0)
{
$_SESSION['_config']['errmsg'] = sprintf(_("The domain '%s' is already in a different account and is listed as valid. Can't continue."), sanitizeHTML($domain));
$id = $oldid;
@@ -2320,23 +2320,23 @@ function buildSubjectFromSession() {
`orgdomlink`.`orgdomid`=`orgdomains`.`id` and
`orgdomaincerts`.`id`=`orgdomlink`.`orgcertid` and
`orgdomains`.`id`='".intval($domid)."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- while($row = mysqli_fetch_assoc($res))
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".$row['id']."'");
+ $res = mysql_query($query);
+ while($row = mysql_fetch_assoc($res))
+ mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".$row['id']."'");
$query = "select `orgemailcerts`.`id` as `id` from `orgemailcerts`, `orgemaillink`, `orgdomains` where
`orgemaillink`.`domid`=`orgdomains`.`id` and
`orgemailcerts`.`id`=`orgemaillink`.`emailcertsid` and
`orgdomains`.`id`='".intval($domid)."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- while($row = mysqli_fetch_assoc($res))
- mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
+ $res = mysql_query($query);
+ while($row = mysql_fetch_assoc($res))
+ mysql_query("update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
}
if($oldid == 29 && $process != "")
{
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `id`='".intval($domid)."'"));
- mysqli_query($_SESSION['mconn'],"update `orgdomains` set `domain`='$domain' where `id`='".intval($domid)."'");
+ $row = mysql_fetch_assoc(mysql_query("select * from `orgdomains` where `id`='".intval($domid)."'"));
+ mysql_query("update `orgdomains` set `domain`='$domain' where `id`='".intval($domid)."'");
showheader(_("My CAcert.org Account!"));
printf(_("'%s' has just been successfully updated in the database."), sanitizeHTML($domain));
echo "
"._("Click here")." "._("to continue.");
@@ -2346,9 +2346,9 @@ function buildSubjectFromSession() {
if($oldid == 30 && $process != "")
{
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `orgdomains` where `id`='".intval($domid)."'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `orgdomains` where `id`='".intval($domid)."'"));
$domain = $row['domain'];
- mysqli_query($_SESSION['mconn'],"delete from `orgdomains` where `id`='".intval($domid)."'");
+ mysql_query("delete from `orgdomains` where `id`='".intval($domid)."'");
showheader(_("My CAcert.org Account!"));
printf(_("'%s' has just been successfully deleted from the database."), sanitizeHTML($domain));
echo "
"._("Click here")." "._("to continue.");
@@ -2365,36 +2365,36 @@ function buildSubjectFromSession() {
if($oldid == 31 && $process != "")
{
$query = "select * from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'";
- $dres = mysqli_query($_SESSION['mconn'],$query);
- while($drow = mysqli_fetch_assoc($dres))
+ $dres = mysql_query($query);
+ while($drow = mysql_fetch_assoc($dres))
{
$query = "select `orgdomaincerts`.`id` as `id` from `orgdomlink`, `orgdomaincerts`, `orgdomains` where
`orgdomlink`.`orgdomid`=`orgdomains`.`id` and
`orgdomaincerts`.`id`=`orgdomlink`.`orgcertid` and
`orgdomains`.`id`='".intval($drow['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- while($row = mysqli_fetch_assoc($res))
+ $res = mysql_query($query);
+ while($row = mysql_fetch_assoc($res))
{
- mysqli_query($_SESSION['mconn'],"update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orgdomaincerts` where `orgid`='".intval($row['id'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orgdomlink` where `domid`='".intval($row['id'])."'");
+ mysql_query("update `orgdomaincerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
+ mysql_query("delete from `orgdomaincerts` where `orgid`='".intval($row['id'])."'");
+ mysql_query("delete from `orgdomlink` where `domid`='".intval($row['id'])."'");
}
$query = "select `orgemailcerts`.`id` as `id` from `orgemailcerts`, `orgemaillink`, `orgdomains` where
`orgemaillink`.`domid`=`orgdomains`.`id` and
`orgemailcerts`.`id`=`orgemaillink`.`emailcertsid` and
`orgdomains`.`id`='".intval($drow['id'])."'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- while($row = mysqli_fetch_assoc($res))
+ $res = mysql_query($query);
+ while($row = mysql_fetch_assoc($res))
{
- mysqli_query($_SESSION['mconn'],"update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orgemailcerts` where `id`='".intval($row['id'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orgemaillink` where `domid`='".intval($row['id'])."'");
+ mysql_query("update `orgemailcerts` set `revoked`='1970-01-01 10:00:01' where `id`='".intval($row['id'])."'");
+ mysql_query("delete from `orgemailcerts` where `id`='".intval($row['id'])."'");
+ mysql_query("delete from `orgemaillink` where `domid`='".intval($row['id'])."'");
}
}
- mysqli_query($_SESSION['mconn'],"delete from `org` where `orgid`='".intval($_SESSION['_config']['orgid'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'");
- mysqli_query($_SESSION['mconn'],"delete from `orginfo` where `id`='".intval($_SESSION['_config']['orgid'])."'");
+ mysql_query("delete from `org` where `orgid`='".intval($_SESSION['_config']['orgid'])."'");
+ mysql_query("delete from `orgdomains` where `orgid`='".intval($_SESSION['_config']['orgid'])."'");
+ mysql_query("delete from `orginfo` where `id`='".intval($_SESSION['_config']['orgid'])."'");
}
if($oldid == 31)
@@ -2406,7 +2406,7 @@ function buildSubjectFromSession() {
if($id == 32 || $oldid == 32 || $id == 33 || $oldid == 33 || $id == 34 || $oldid == 34)
{
$query = "select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'";
- $_macc = mysqli_num_rows(mysqli_query($_SESSION['mconn'],$query));
+ $_macc = mysql_num_rows(mysql_query($query));
if($_SESSION['profile']['orgadmin'] != 1 && $_macc <= 0)
{
showheader(_("My CAcert.org Account!"));
@@ -2419,7 +2419,7 @@ function buildSubjectFromSession() {
if($id == 35 || $oldid == 35)
{
$query = "select 1 from `org` where `memid`='".intval($_SESSION['profile']['id'])."'";
- $is_orguser = mysqli_num_rows(mysqli_query($_SESSION['mconn'],$query));
+ $is_orguser = mysql_num_rows(mysql_query($query));
if($_SESSION['profile']['orgadmin'] != 1 && $is_orguser <= 0)
{
showheader(_("My CAcert.org Account!"));
@@ -2433,8 +2433,8 @@ function buildSubjectFromSession() {
{
$orgid = intval($_SESSION['_config']['orgid']);
$query = "select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
$id = 35;
}
@@ -2447,17 +2447,17 @@ function buildSubjectFromSession() {
$masteracc = $_SESSION['_config']['masteracc'] = intval($_REQUEST['masteracc']);
else
$masteracc = $_SESSION['_config']['masteracc'] = 0;
- $_REQUEST['email'] = $_SESSION['_config']['email'] = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['email'])));
+ $_REQUEST['email'] = $_SESSION['_config']['email'] = mysql_real_escape_string(stripslashes(trim($_REQUEST['email'])));
$_SESSION['_config']['OU'] = stripslashes(trim($_REQUEST['OU']));
- $comments = $_SESSION['_config']['comments'] = mysqli_real_escape_string($_SESSION['mconn'], stripslashes(trim($_REQUEST['comments'])));
- $res = mysqli_query($_SESSION['mconn'],"select * from `users` where `email`='".$_REQUEST['email']."' and `deleted`=0");
- if(mysqli_num_rows($res) <= 0)
+ $comments = $_SESSION['_config']['comments'] = mysql_real_escape_string(stripslashes(trim($_REQUEST['comments'])));
+ $res = mysql_query("select * from `users` where `email`='".$_REQUEST['email']."' and `deleted`=0");
+ if(mysql_num_rows($res) <= 0)
{
$id = $oldid;
$oldid=0;
$_SESSION['_config']['errmsg'] = sprintf(_("Wasn't able to match '%s' against any user in the system"), sanitizeHTML($_REQUEST['email']));
} else {
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
if ( !is_assurer(intval($row['id'])) )
{
$id = $oldid;
@@ -2465,12 +2465,12 @@ function buildSubjectFromSession() {
$_SESSION['_config']['errmsg'] =
_("The user is not an Assurer yet");
} else {
- mysqli_query($_SESSION['mconn'],
+ mysql_query(
"insert into `org`
set `memid`='".intval($row['id'])."',
`orgid`='".intval($_SESSION['_config']['orgid'])."',
`masteracc`='$masteracc',
- `OU`='".mysqli_real_escape_string($_SESSION['mconn'], $_SESSION['_config']['OU'])."',
+ `OU`='".mysql_real_escape_string($_SESSION['_config']['OU'])."',
`comments`='$comments'");
}
}
@@ -2479,8 +2479,8 @@ function buildSubjectFromSession() {
if(($oldid == 34 || $id == 34) && $_SESSION['profile']['orgadmin'] != 1)
{
$orgid = intval($_SESSION['_config']['orgid']);
- $res = mysqli_query($_SESSION['mconn'],"select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'");
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query("select * from `org` where `orgid`='$orgid' and `memid`='".intval($_SESSION['profile']['id'])."' and `masteracc`='1'");
+ if(mysql_num_rows($res) <= 0)
$id = 32;
}
@@ -2489,7 +2489,7 @@ function buildSubjectFromSession() {
$orgid = intval($_SESSION['_config']['orgid']);
$memid = intval($_REQUEST['memid']);
$query = "delete from `org` where `orgid`='$orgid' and `memid`='$memid'";
- mysqli_query($_SESSION['mconn'],$query);
+ mysql_query($query);
}
if($oldid == 34 || $oldid == 33)
@@ -2501,7 +2501,7 @@ function buildSubjectFromSession() {
if($id == 36)
{
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'"));
$_REQUEST['general'] = $row['general'];
$_REQUEST['country'] = $row['country'];
$_REQUEST['regional'] = $row['regional'];
@@ -2510,7 +2510,7 @@ function buildSubjectFromSession() {
if($oldid == 36)
{
- $rc = mysqli_num_rows(mysqli_query($_SESSION['mconn'],"select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'"));
+ $rc = mysql_num_rows(mysql_query("select * from `alerts` where `memid`='".intval($_SESSION['profile']['id'])."'"));
if($rc > 0)
{
$query = "update `alerts` set `general`='".intval(array_key_exists('general',$_REQUEST)?$_REQUEST['general']:0)."',
@@ -2525,7 +2525,7 @@ function buildSubjectFromSession() {
`radius`='".intval(array_key_exists('radius',$_REQUEST)?$_REQUEST['radius']:0)."',
`memid`='".intval($_SESSION['profile']['id'])."'";
}
- mysqli_query($_SESSION['mconn'],$query);
+ mysql_query($query);
$id = $oldid;
$oldid=0;
}
@@ -2533,12 +2533,12 @@ function buildSubjectFromSession() {
if($oldid == 41 && $_REQUEST['action'] == 'default')
{
csrf_check("mainlang");
- $lang = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['lang']);
+ $lang = mysql_real_escape_string($_REQUEST['lang']);
foreach(L10n::$translations as $key => $val)
{
if($key == $lang)
{
- mysqli_query($_SESSION['mconn'],"update `users` set `language`='$lang' where `id`='".intval($_SESSION['profile']['id'])."'");
+ mysql_query("update `users` set `language`='$lang' where `id`='".intval($_SESSION['profile']['id'])."'");
$_SESSION['profile']['language'] = $lang;
showheader(_("My CAcert.org Account!"));
echo _("Your language setting has been updated.");
@@ -2556,9 +2556,9 @@ function buildSubjectFromSession() {
if($oldid == 41 && $_REQUEST['action'] == 'addsec')
{
csrf_check("seclang");
- $addlang = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['addlang']);
+ $addlang = mysql_real_escape_string($_REQUEST['addlang']);
// Does the language exist?
- mysqli_query($_SESSION['mconn'],"insert into `addlang` set `userid`='".intval($_SESSION['profile']['id'])."', `lang`='$addlang'");
+ mysql_query("insert into `addlang` set `userid`='".intval($_SESSION['profile']['id'])."', `lang`='$addlang'");
showheader(_("My CAcert.org Account!"));
echo _("Your language setting has been updated.");
showfooter();
@@ -2568,8 +2568,8 @@ function buildSubjectFromSession() {
if($oldid == 41 && $_REQUEST['action'] == 'dellang')
{
csrf_check("seclang");
- $remove = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['remove']);
- mysqli_query($_SESSION['mconn'],"delete from `addlang` where `userid`='".intval($_SESSION['profile']['id'])."' and `lang`='$remove'");
+ $remove = mysql_real_escape_string($_REQUEST['remove']);
+ mysql_query("delete from `addlang` where `userid`='".intval($_SESSION['profile']['id'])."' and `lang`='$remove'");
showheader(_("My CAcert.org Account!"));
echo _("Your language setting has been updated.");
showfooter();
@@ -2604,7 +2604,7 @@ function buildSubjectFromSession() {
$regid = intval(array_key_exists('regid',$_REQUEST)?$_REQUEST['regid']:0);
$newreg = intval(array_key_exists('newreg',$_REQUEST)?$_REQUEST['newreg']:0);
$locid = intval(array_key_exists('locid',$_REQUEST)?$_REQUEST['locid']:0);
- $name = array_key_exists('name',$_REQUEST)?mysqli_real_escape_string($_SESSION['mconn'], strip_tags($_REQUEST['name'])):"";
+ $name = array_key_exists('name',$_REQUEST)?mysql_real_escape_string(strip_tags($_REQUEST['name'])):"";
$long = array_key_exists('longitude',$_REQUEST)?ereg_replace("[^-0-9\.]","",$_REQUEST['longitude']):"";
$lat = array_key_exists('latitude', $_REQUEST)?ereg_replace("[^-0-9\.]","",$_REQUEST['latitude']):"";
$action = array_key_exists('action',$_REQUEST)?$_REQUEST['action']:"";
@@ -2612,58 +2612,58 @@ function buildSubjectFromSession() {
if($locid > 0 && $action == "edit")
{
$query = "update `locations` set `name`='$name', `lat`='$lat', `long`='$long' where `id`='$locid'";
- mysqli_query($_SESSION['mconn'],$query);
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'"));
+ mysql_query($query);
+ $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'"));
$_REQUEST['regid'] = $row['regid'];
unset($_REQUEST['ccid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($regid > 0 && $action == "edit") {
$query = "update `regions` set `name`='$name' where `id`='$regid'";
- mysqli_query($_SESSION['mconn'],$query);
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `regions` where `id`='$regid'"));
+ mysql_query($query);
+ $row = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'"));
$_REQUEST['ccid'] = $row['ccid'];
unset($_REQUEST['regid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($regid > 0 && $action == "add") {
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select `ccid` from `regions` where `id`='$regid'"));
+ $row = mysql_fetch_assoc(mysql_query("select `ccid` from `regions` where `id`='$regid'"));
$ccid = $row['ccid'];
$query = "insert into `locations` set `ccid`='$ccid', `regid`='$regid', `name`='$name', `lat`='$lat', `long`='$long'";
- mysqli_query($_SESSION['mconn'],$query);
+ mysql_query($query);
unset($_REQUEST['ccid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($ccid > 0 && $action == "add" && $name != "") {
$query = "insert into `regions` set `ccid`='$ccid', `name`='$name'";
- mysqli_query($_SESSION['mconn'],$query);
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'"));
+ mysql_query($query);
+ $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'"));
unset($_REQUEST['regid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($locid > 0 && $action == "delete") {
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'"));
$_REQUEST['regid'] = $row['regid'];
- mysqli_query($_SESSION['mconn'],"delete from `localias` where `locid`='$locid'");
- mysqli_query($_SESSION['mconn'],"delete from `locations` where `id`='$locid'");
+ mysql_query("delete from `localias` where `locid`='$locid'");
+ mysql_query("delete from `locations` where `id`='$locid'");
unset($_REQUEST['ccid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($locid > 0 && $action == "move") {
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'"));
$oldregid = $row['regid'];
- mysqli_query($_SESSION['mconn'],"update `locations` set `regid`='$newreg' where `id`='$locid'");
- mysqli_query($_SESSION['mconn'],"update `users` set `regid`='$newreg' where `regid`='$oldregid'");
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `locations` where `id`='$locid'"));
+ mysql_query("update `locations` set `regid`='$newreg' where `id`='$locid'");
+ mysql_query("update `users` set `regid`='$newreg' where `regid`='$oldregid'");
+ $row = mysql_fetch_assoc(mysql_query("select * from `locations` where `id`='$locid'"));
$_REQUEST['regid'] = $row['regid'];
unset($_REQUEST['ccid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
} else if($regid > 0 && $action == "delete") {
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `regions` where `id`='$regid'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `regions` where `id`='$regid'"));
$_REQUEST['ccid'] = $row['ccid'];
- mysqli_query($_SESSION['mconn'],"delete from `locations` where `regid`='$regid'");
- mysqli_query($_SESSION['mconn'],"delete from `regions` where `id`='$regid'");
+ mysql_query("delete from `locations` where `regid`='$regid'");
+ mysql_query("delete from `regions` where `id`='$regid'");
unset($_REQUEST['regid']);
unset($_REQUEST['locid']);
unset($_REQUEST['action']);
@@ -2672,12 +2672,12 @@ function buildSubjectFromSession() {
$_REQUEST['action'] = "aliases";
$_REQUEST['locid'] = $locid;
$name = htmlentities($name);
- $row = mysqli_query($_SESSION['mconn'],"insert into `localias` set `locid`='$locid',`name`='$name'");
+ $row = mysql_query("insert into `localias` set `locid`='$locid',`name`='$name'");
} else if($locid > 0 && $action == "delalias") {
$id = 54;
$_REQUEST['action'] = "aliases";
$_REQUEST['locid'] = $locid;
- $row = mysqli_query($_SESSION['mconn'],"delete from `localias` where `locid`='$locid' and `name`='$name'");
+ $row = mysql_query("delete from `localias` where `locid`='$locid' and `name`='$name'");
}
}
@@ -2714,15 +2714,15 @@ function buildSubjectFromSession() {
showfooter();
exit;
}
- $fname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['fname']);
- $mname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['mname']);
- $lname = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['lname']);
- $suffix = mysqli_real_escape_string($_SESSION['mconn'], $_REQUEST['suffix']);
+ $fname = mysql_real_escape_string($_REQUEST['fname']);
+ $mname = mysql_real_escape_string($_REQUEST['mname']);
+ $lname = mysql_real_escape_string($_REQUEST['lname']);
+ $suffix = mysql_real_escape_string($_REQUEST['suffix']);
$day = intval($_REQUEST['day']);
$month = intval($_REQUEST['month']);
$year = intval($_REQUEST['year']);
$query = "update `users` set `fname`='$fname',`mname`='$mname',`lname`='$lname',`suffix`='$suffix',`dob`='$year-$month-$day' where `id`='$userid'";
- mysqli_query($_SESSION['mconn'],$query);
+ mysql_query($query);
}elseif($oldid == 43 && $actionrequest == "updatedob" && $ticketvalidation == FALSE){
$id = 43;
$oldid=0;
@@ -2761,7 +2761,7 @@ function buildSubjectFromSession() {
if($id == 44)
{
$_REQUEST['userid'] = intval($_REQUEST['userid']);
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
if($row['email'] == "")
$id = 42;
else
@@ -2781,8 +2781,8 @@ function buildSubjectFromSession() {
showfooter();
exit;
}
- mysqli_query($_SESSION['mconn'],"update `users` set `password`=sha1('".mysqli_real_escape_string($_SESSION['mconn'], stripslashes($_REQUEST['newpass']))."') where `id`='".intval($_REQUEST['userid'])."'");
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
+ mysql_query("update `users` set `password`=sha1('".mysql_real_escape_string(stripslashes($_REQUEST['newpass']))."') where `id`='".intval($_REQUEST['userid'])."'");
+ $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
printf(_("The password for %s has been updated successfully in the system."), sanitizeHTML($row['email']));
$my_translation = L10n::get_translation();
@@ -2872,24 +2872,24 @@ function buildSubjectFromSession() {
`CN`='".$_SESSION['_config']['0.CN']."',
`domid`='".$_SESSION['_config']['row']['id']."',
`created`=NOW()";
- mysqli_query($_SESSION['mconn'],$query);
- $CSRid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $CSRid = mysql_insert_id();
foreach($_SESSION['_config']['rowid'] as $dom)
- mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'");
+ mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'");
if(is_array($_SESSION['_config']['altid']))
foreach($_SESSION['_config']['altid'] as $dom)
- mysqli_query($_SESSION['mconn'],"insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'");
+ mysql_query("insert into `domlink` set `certid`='$CSRid', `domid`='".intval($dom)."'");
$CSRname=generatecertpath("csr","server",$CSRid);
$fp = fopen($CSRname, "w");
fputs($fp, $_SESSION['_config']['CSR']);
fclose($fp);
- mysqli_query($_SESSION['mconn'],"update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
+ mysql_query("update `domaincerts` set `CSR_name`='$CSRname' where `id`='$CSRid'");
waitForResult("domaincerts", $CSRid,$oldid);
$query = "select * from `domaincerts` where `id`='$CSRid' and `crt_name` != ''";
- $res = mysqli_query($_SESSION['mconn'],$query);
- if(mysqli_num_rows($res) <= 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <= 0)
{
showheader(_("My CAcert.org Account!"));
printf(_("Your certificate request has failed to be processed correctly, see %sthe WIKI page%s for reasons and solutions."), "", "");
@@ -2913,9 +2913,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['tverify'];
- mysqli_query($_SESSION['mconn'],"update `users` set `tverify`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `tverify`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('tverify',$_REQUEST) && $_REQUEST['tverify'] > 0 && $ticketvalidation==FALSE){
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
}
@@ -2932,9 +2932,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['assurer'];
- mysqli_query($_SESSION['mconn'],"update `users` set `assurer`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `assurer`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('assurer',$_REQUEST) && $_REQUEST['assurer'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['assurer']);
$_SESSION['ticketmsg']='No action (Change assurer status) taken. Ticket number is missing!';
@@ -2950,9 +2950,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['assurer_blocked'];
- mysqli_query($_SESSION['mconn'],"update `users` set `assurer_blocked`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `assurer_blocked`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('assurer_blocked',$_REQUEST) && $_REQUEST['assurer_blocked'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['assurer_blocked']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -2969,9 +2969,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['locked'];
- mysqli_query($_SESSION['mconn'],"update `users` set `locked`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `locked`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('locked',$_REQUEST) && $_REQUEST['locked'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['locked']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -2988,9 +2988,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['codesign'];
- mysqli_query($_SESSION['mconn'],"update `users` set `codesign`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `codesign`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('codesign',$_REQUEST) && $_REQUEST['codesign'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['codesign']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3007,9 +3007,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['orgadmin'];
- mysqli_query($_SESSION['mconn'],"update `users` set `orgadmin`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `orgadmin`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('orgadmin',$_REQUEST) && $_REQUEST['orgadmin'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['orgadmin']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3026,9 +3026,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['ttpadmin'];
- mysqli_query($_SESSION['mconn'],"update `users` set `ttpadmin`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `ttpadmin`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('ttpadmin',$_REQUEST) && $_REQUEST['ttpadmin'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['ttpadmin']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3044,11 +3044,11 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = $row['adadmin'] + 1;
if($ver > 2)
$ver = 0;
- mysqli_query($_SESSION['mconn'],"update `users` set `adadmin`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `adadmin`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('adadmin',$_REQUEST) && $_REQUEST['adadmin'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['adadmin']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3064,9 +3064,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['locadmin'];
- mysqli_query($_SESSION['mconn'],"update `users` set `locadmin`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `locadmin`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('locadmin',$_REQUEST) && $_REQUEST['locadmin'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['locadmin']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3083,9 +3083,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `users` where `id`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['admin'];
- mysqli_query($_SESSION['mconn'],"update `users` set `admin`='$ver' where `id`='$memid'");
+ mysql_query("update `users` set `admin`='$ver' where `id`='$memid'");
}elseif($id == 43 && array_key_exists('admin',$_REQUEST) && $_REQUEST['admin'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['admin']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3101,9 +3101,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `alerts` where `memid`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['general'];
- mysqli_query($_SESSION['mconn'],"update `alerts` set `general`='$ver' where `memid`='$memid'");
+ mysql_query("update `alerts` set `general`='$ver' where `memid`='$memid'");
}elseif($id == 43 && array_key_exists('general',$_REQUEST) && $_REQUEST['general'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['general']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3119,9 +3119,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `alerts` where `memid`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['country'];
- mysqli_query($_SESSION['mconn'],"update `alerts` set `country`='$ver' where `memid`='$memid'");
+ mysql_query("update `alerts` set `country`='$ver' where `memid`='$memid'");
}elseif($id == 43 && array_key_exists('country',$_REQUEST) && $_REQUEST['country'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['country']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3137,9 +3137,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `alerts` where `memid`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['regional'];
- mysqli_query($_SESSION['mconn'],"update `alerts` set `regional`='$ver' where `memid`='$memid'");
+ mysql_query("update `alerts` set `regional`='$ver' where `memid`='$memid'");
}elseif($id == 43 && array_key_exists('regional',$_REQUEST) && $_REQUEST['regional'] > 0 && $ticketvalidation == FALSE){
$_REQUEST['userid'] = intval($_REQUEST['regional']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3155,9 +3155,9 @@ function buildSubjectFromSession() {
exit;
}
$query = "select * from `alerts` where `memid`='$memid'";
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],$query));
+ $row = mysql_fetch_assoc(mysql_query($query));
$ver = !$row['radius'];
- mysqli_query($_SESSION['mconn'],"update `alerts` set `radius`='$ver' where `memid`='$memid'");
+ mysql_query("update `alerts` set `radius`='$ver' where `memid`='$memid'");
}elseif($id == 43 && array_key_exists('radius',$_REQUEST) && $_REQUEST['radius'] > 0 && $ticketvalidation == false){
$_REQUEST['userid'] = intval($_REQUEST['radius']);
$_SESSION['ticketmsg']='No action taken. Ticket number is missing!';
@@ -3169,7 +3169,7 @@ function buildSubjectFromSession() {
$_REQUEST['userid'] = intval($_REQUEST['userid']);
}
- $row = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],"select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
+ $row = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($_REQUEST['userid'])."'"));
if($row['email'] == "") {
$id = 42;
} else {
diff --git a/includes/account_stuff.php b/includes/account_stuff.php
index 71314d1..0fda2f1 100644
--- a/includes/account_stuff.php
+++ b/includes/account_stuff.php
@@ -206,7 +206,7 @@ function hideall() {
+ =_("Server Certificates")?>
- if(mysqli_num_rows(mysqli_query($_SESSION['mconn'], "select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."'")) > 0 || $_SESSION['profile']['orgadmin'] == 1) { ?>
+ if(mysql_num_rows(mysql_query("select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."'")) > 0 || $_SESSION['profile']['orgadmin'] == 1) { ?>
} ?>
- if(mysqli_num_rows(mysqli_query($_SESSION['mconn'], "select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."'")) > 0 || $_SESSION['profile']['orgadmin'] == 1) { ?>
+ if(mysql_num_rows(mysql_query("select * from `org` where `memid`='".intval($_SESSION['profile']['id'])."'")) > 0 || $_SESSION['profile']['orgadmin'] == 1) { ?>
diff --git a/includes/lib/account.php b/includes/lib/account.php
index 26a29ce..dd8afd3 100644
--- a/includes/lib/account.php
+++ b/includes/lib/account.php
@@ -55,7 +55,7 @@ function fix_assurer_flag($userID = NULL)
AND `n`.`deleted` = 0
) >= 100';
- $query = mysqli_query($_SESSION['mconn'], $sql);
+ $query = mysql_query($sql);
if (!$query) {
return false;
}
@@ -91,7 +91,7 @@ function fix_assurer_flag($userID = NULL)
) < 100
)';
- $query = mysqli_query($_SESSION['mconn'], $sql);
+ $query = mysql_query($sql);
if (!$query) {
return false;
}
diff --git a/includes/lib/general.php b/includes/lib/general.php
index 0ba4314..127c6b7 100644
--- a/includes/lib/general.php
+++ b/includes/lib/general.php
@@ -32,15 +32,15 @@
function get_user_id_from_cert($serial, $issuer_cn)
{
$query = "select `memid` from `emailcerts` where
- `serial`='".mysqli_real_escape_string($_SESSION['mconn'], $serial)."' and
+ `serial`='".mysql_escape_string($serial)."' and
`rootcert`= (select `id` from `root_certs` where
- `Cert_Text`='".mysqli_real_escape_string($_SESSION['mconn'], $issuer_cn)."') and
+ `Cert_Text`='".mysql_escape_string($issuer_cn)."') and
`revoked`=0 and disablelogin=0 and
UNIX_TIMESTAMP(`expire`) - UNIX_TIMESTAMP() > 0";
- $res = mysqli_query($_SESSION['mconn'], $query);
- if(mysqli_num_rows($res) > 0)
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) > 0)
{
- $row = mysqli_fetch_assoc($res);
+ $row = mysql_fetch_assoc($res);
return intval($row['memid']);
}
@@ -139,21 +139,21 @@ function runCommand($command, $input = "", &$output = null, &$errors = true) {
function get_assurer_status($userID)
{
$Result = 0;
- $query = mysqli_query($_SESSION['mconn'], 'SELECT * FROM `cats_passed` AS `tp`, `cats_variant` AS `cv` '.
+ $query = mysql_query('SELECT * FROM `cats_passed` AS `tp`, `cats_variant` AS `cv` '.
' WHERE `tp`.`variant_id` = `cv`.`id` AND `cv`.`type_id` = 1 AND `tp`.`user_id` = \''.(int)intval($userID).'\'');
- if(mysqli_num_rows($query) < 1)
+ if(mysql_num_rows($query) < 1)
{
$Result |= 5;
}
- $query = mysqli_query($_SESSION['mconn'], 'SELECT SUM(`points`) AS `points` FROM `notary` AS `n` WHERE `n`.`to` = \''.(int)intval($userID).'\' AND `n`.`expire` < now() and `deleted` = 0');
- $row = mysqli_fetch_assoc($query);
+ $query = mysql_query('SELECT SUM(`points`) AS `points` FROM `notary` AS `n` WHERE `n`.`to` = \''.(int)intval($userID).'\' AND `n`.`expire` < now() and `deleted` = 0');
+ $row = mysql_fetch_assoc($query);
if ($row['points'] < 100) {
$Result |= 3;
}
- $query = mysqli_query($_SESSION['mconn'], 'SELECT `assurer_blocked` FROM `users` WHERE `id` = \''.(int)intval($userID).'\'');
- $row = mysqli_fetch_assoc($query);
+ $query = mysql_query('SELECT `assurer_blocked` FROM `users` WHERE `id` = \''.(int)intval($userID).'\'');
+ $row = mysql_fetch_assoc($query);
if ($row['assurer_blocked'] > 0) {
$Result |= 9;
}
diff --git a/includes/lib/l10n.php b/includes/lib/l10n.php
index 23b21b8..4859946 100644
--- a/includes/lib/l10n.php
+++ b/includes/lib/l10n.php
@@ -170,7 +170,7 @@ class L10n {
foreach($languages as $lang => $qvalue)
{
// ignore any non-conforming values (that's why we don't need to
- // mysqli_real_escape_string($_SESSION['mconn'], ) or escapeshellarg(), but take care of
+ // mysql_real_escape() or escapeshellarg(), but take care of
// the '*')
// spec: ( ( 1*8ALPHA *( "-" 1*8ALPHA ) ) | "*" )
if ( preg_match('/^(?:([a-zA-Z]{1,8})(?:-[a-zA-Z]{1,8})*|\*)$/',
@@ -360,9 +360,9 @@ class L10n {
//returns the language of a recipient to make sure that the language is correct
//use together with
$query = "select `language` from `users` where `id`='".intval($accountid)."'";
- $res = mysqli_query($_SESSION['mconn'], $query);
- if (mysqli_num_rows($res)>=0) {
- $row = mysqli_fetch_assoc($res);
+ $res = mysql_query($query);
+ if (mysql_num_rows($res)>=0) {
+ $row = mysql_fetch_assoc($res);
if (NULL==$row['language'] || $row['language']=='') {
self::set_translation('en');
} else {
diff --git a/includes/loggedin.php b/includes/loggedin.php
index 5bf157a..c14f8c2 100644
--- a/includes/loggedin.php
+++ b/includes/loggedin.php
@@ -44,7 +44,7 @@
//session_unregister($key);
}
- $_SESSION['profile'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `users` where `id`='".intval($uid)."'"));
+ $_SESSION['profile'] = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='".intval($uid)."'"));
if($_SESSION['profile']['locked'] == 0)
$_SESSION['profile']['loggedin'] = 1;
else
@@ -70,7 +70,7 @@
//session_unregister($key);
}
- $_SESSION['profile'] = mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'],
+ $_SESSION['profile'] = mysql_fetch_assoc(mysql_query(
"select * from `users` where `id`='".intval($user_id)."'"));
if($_SESSION['profile']['locked'] == 0)
$_SESSION['profile']['loggedin'] = 1;
@@ -103,15 +103,15 @@
if($_SERVER['HTTP_HOST'] == $_SESSION['_config']['securehostname'] && $_SESSION['profile']['id'] > 0 && $_SESSION['profile']['loggedin'] > 0)
{
$query = "select sum(`points`) as `total` from `notary` where `to`='".intval($_SESSION['profile']['id'])."' and `deleted` = 0 group by `to`";
- $res = mysqli_query($_SESSION['mconn'], $query);
- $row = mysqli_fetch_assoc($res);
+ $res = mysql_query($query);
+ $row = mysql_fetch_assoc($res);
$_SESSION['profile']['points'] = $row['total'];
if($_SESSION['profile']['language'] == "")
{
$query = "update `users` set `language`='".L10n::get_translation()."'
where `id`='".intval($_SESSION['profile']['id'])."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
} else {
L10n::set_translation($_SESSION['profile']['language']);
L10n::init_gettext();
diff --git a/includes/mysql.php.sample b/includes/mysql.php.sample
index befe079..77be95f 100644
--- a/includes/mysql.php.sample
+++ b/includes/mysql.php.sample
@@ -16,14 +16,13 @@
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
*/
- $_SESSION['mconn'] = mysqli_connect("127.0.0.1", "username", "password", "database");
-
-// if (!$_SESSION['mconn']) {
-// die('Connect Error (' . mysqli_connect_errno() . ') '
-// . mysqli_connect_error());
-// }
-
- $_SESSION['_config']['normalhostname'] = "www.cacert.org";
+ $_SESSION['mconn'] = mysql_connect("127.0.0.1", "username", "password");
+ if ($_SESSION['mconn'] != FALSE)
+ {
+ mysql_select_db("database");
+ $_SESSION['mconn'] = TRUE;
+ }
+ $_SESSION['_config']['normalhostname'] = "www.cacert.org";
$_SESSION['_config']['securehostname'] = "secure.cacert.org";
$_SESSION['_config']['tverify'] = "tverify.cacert.org";
diff --git a/includes/notary.inc.php b/includes/notary.inc.php
index a4c8ee7..3b8e736 100644
--- a/includes/notary.inc.php
+++ b/includes/notary.inc.php
@@ -21,18 +21,18 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function query_init ($query)
{
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
function query_getnextrow ($res)
{
- $row1 = mysqli_fetch_assoc($res);
+ $row1 = mysql_fetch_assoc($res);
return $row1;
}
function query_get_number_of_rows ($resultset)
{
- return intval(mysqli_num_rows($resultset));
+ return intval(mysql_num_rows($resultset));
}
function get_number_of_assurances ($userid)
@@ -125,7 +125,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function get_user ($userid)
{
$res = query_init ("select * from `users` where `id`='".intval($userid)."'");
- return mysqli_fetch_assoc($res);
+ return mysql_fetch_assoc($res);
}
function get_cats_state ($userid)
@@ -133,7 +133,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
$res = query_init ("select * from `cats_passed` inner join `cats_variant` on `cats_passed`.`variant_id` = `cats_variant`.`id` and `cats_variant`.`type_id` = 1
WHERE `cats_passed`.`user_id` = '".intval($userid)."'");
- return mysqli_num_rows($res);
+ return mysql_num_rows($res);
}
@@ -587,7 +587,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
$sum_points = 0;
$sumexperience = 0;
$res = get_given_assurances(intval($userid), $log);
- while($row = mysqli_fetch_assoc($res))
+ while($row = mysql_fetch_assoc($res))
{
$assuree = get_user(intval($row['to']));
calc_experience($row, $sum_points, $sum_experience);
@@ -617,7 +617,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
$sum_points = 0;
$sumexperience = 0;
$res = get_received_assurances(intval($userid), $log);
- while($row = mysqli_fetch_assoc($res))
+ while($row = mysql_fetch_assoc($res))
{
$fromuser = get_user(intval($row['from']));
calc_assurances($row, $sum_points, $sum_experience);
@@ -661,7 +661,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
}
$res = get_received_assurances_summary($userid);
- while($row = mysqli_fetch_assoc($res))
+ while($row = mysql_fetch_assoc($res))
{
$points = calc_awarded($row);
@@ -674,7 +674,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
}
$res = get_given_assurances_summary($userid);
- while($row = mysqli_fetch_assoc($res))
+ while($row = mysql_fetch_assoc($res))
{
switch ($row['method'])
{
@@ -860,8 +860,8 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function write_user_agreement($memid, $document, $method, $comment, $active=1, $secmemid=0){
// write a new record to the table user_agreement
$query="insert into `user_agreements` set `memid`=".intval($memid).", `secmemid`=".intval($secmemid).
- ",`document`='".mysqli_real_escape_string($_SESSION['mconn'], $document)."',`date`=NOW(), `active`=".intval($active).",`method`='".mysqli_real_escape_string($_SESSION['mconn'], $method)."',`comment`='".mysqli_real_escape_string($_SESSION['mconn'], $comment)."'" ;
- $res = mysqli_query($_SESSION['mconn'], $query);
+ ",`document`='".mysql_real_escape_string($document)."',`date`=NOW(), `active`=".intval($active).",`method`='".mysql_real_escape_string($method)."',`comment`='".mysql_real_escape_string($comment)."'" ;
+ $res = mysql_query($query);
}
/**
@@ -873,9 +873,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
*/
function get_user_agreement_status($memid, $type="CCA"){
$query="SELECT u.`document` FROM `user_agreements` u
- WHERE u.`document` = '" . mysqli_real_escape_string($_SESSION['mconn'], $type) . "' AND u.`memid`=" . intval($memid) ;
- $res = mysqli_query($_SESSION['mconn'], $query);
- if(mysqli_num_rows($res) <=0){
+ WHERE u.`document` = '" . mysql_real_escape_string($type) . "' AND u.`memid`=" . intval($memid) ;
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) <=0){
return 0;
}else{
return 1;
@@ -897,7 +897,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function get_first_user_agreement($memid, $type=null, $active=null){
$filter = '';
if (!is_null($type)) {
- $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'";
+ $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'";
}
if (!is_null($active)) {
@@ -908,9 +908,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
WHERE u.`memid`=".intval($memid)."
$filter
ORDER BY u.`date` LIMIT 1";
- $res = mysqli_query($_SESSION['mconn'], $query);
- if(mysqli_num_rows($res) >0){
- $rec = mysqli_fetch_assoc($res);
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) >0){
+ $rec = mysql_fetch_assoc($res);
}else{
$rec=array();
}
@@ -932,7 +932,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function get_last_user_agreement($memid, $type=null, $active=null){
$filter = '';
if (!is_null($type)) {
- $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'";
+ $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'";
}
if (!is_null($active)) {
@@ -943,9 +943,9 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
WHERE u.`memid`=".intval($memid)."
$filter
ORDER BY u.`date` DESC LIMIT 1";
- $res = mysqli_query($_SESSION['mconn'], $query);
- if(mysqli_num_rows($res) >0){
- $rec = mysqli_fetch_assoc($res);
+ $res = mysql_query($query);
+ if(mysql_num_rows($res) >0){
+ $rec = mysql_fetch_assoc($res);
}else{
$rec=array();
}
@@ -966,7 +966,7 @@ define('THAWTE_REVOCATION_DATETIME', '2010-11-16 00:00:00');
function get_user_agreements($memid, $type=null, $active=null){
$filter = '';
if (!is_null($type)) {
- $filter .= " AND u.`document` = '".mysqli_real_escape_string($_SESSION['mconn'], $type)."'";
+ $filter .= " AND u.`document` = '".mysql_real_escape_string($type)."'";
}
if (!is_null($active)) {
@@ -977,7 +977,7 @@ function get_user_agreements($memid, $type=null, $active=null){
WHERE u.`memid`=".intval($memid)."
$filter
ORDER BY u.`date`";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -991,9 +991,9 @@ function get_user_agreements($memid, $type=null, $active=null){
if ($type === false) {
$filter = '';
} else {
- $filter = " and `document` = '" . mysqli_real_escape_string($_SESSION['mconn'], $type) . "'";
+ $filter = " and `document` = '" . mysql_real_escape_string($type) . "'";
}
- mysqli_query($_SESSION['mconn'], "delete from `user_agreements` where `memid`=" . intval($memid) . $filter );
+ mysql_query("delete from `user_agreements` where `memid`=" . intval($memid) . $filter );
}
// functions for 6.php (assure somebody)
@@ -1095,7 +1095,7 @@ function get_user_agreements($memid, $type=null, $active=null){
$mailid = intval($mailid);
revoke_all_client_cert($mailid);
$query = "update `email` set `deleted`=NOW() where `id`='$mailid'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
}
function account_domain_delete($domainid){
@@ -1106,7 +1106,7 @@ function get_user_agreements($memid, $type=null, $active=null){
//called from account_delete
$domainid = intval($domainid);
revoke_all_server_cert($domainid);
- mysqli_query($_SESSION['mconn'],
+ mysql_query(
"update `domains`
set `deleted`=NOW()
where `id` = '$domainid'");
@@ -1117,7 +1117,7 @@ function get_user_agreements($memid, $type=null, $active=null){
// called from www/account.php if($oldid == 50 && $process != "")
//change password
$id = intval($id);
- $arbno = mysqli_real_escape_string($_SESSION['mconn'], $arbno);
+ $arbno = mysql_real_escape_string($arbno);
$adminid = intval($adminid);
$pool = 'abcdefghijklmnopqrstuvwxyz';
$pool .= '0123456789!()§';
@@ -1128,33 +1128,33 @@ function get_user_agreements($memid, $type=null, $active=null){
{
$password .= substr($pool,(rand()%(strlen ($pool))), 1);
}
- mysqli_query($_SESSION['mconn'], "update `users` set `password`=sha1('".$password."') where `id`='".$id."'");
+ mysql_query("update `users` set `password`=sha1('".$password."') where `id`='".$id."'");
//create new mail for arbitration number
$query = "insert into `email` set `email`='".$arbno."@cacert.org',`memid`='".$id."',`created`=NOW(),`modified`=NOW(), `attempts`=-1";
- mysqli_query($_SESSION['mconn'], $query);
- $emailid = mysqli_insert_id($_SESSION['mconn']);
+ mysql_query($query);
+ $emailid = mysql_insert_id();
//set new mail as default
$query = "update `users` set `email`='".$arbno."@cacert.org' where `id`='".$id."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
//delete all other email address
$query = "select `id` from `email` where `memid`='".$id."' and `id`!='".$emailid."'" ;
- $res=mysqli_query($_SESSION['mconn'], $query);
- while($row = mysqli_fetch_assoc($res)){
+ $res=mysql_query($query);
+ while($row = mysql_fetch_assoc($res)){
account_email_delete($row['id']);
}
//delete all domains
$query = "select `id` from `domains` where `memid`='".$id."'";
- $res=mysqli_query($_SESSION['mconn'], $query);
- while($row = mysqli_fetch_assoc($res)){
+ $res=mysql_query($query);
+ while($row = mysql_fetch_assoc($res)){
account_domain_delete($row['id']);
}
//clear alert settings
- mysqli_query($_SESSION['mconn'],
+ mysql_query(
"update `alerts` set
`general`='0',
`country`='0',
@@ -1164,17 +1164,17 @@ function get_user_agreements($memid, $type=null, $active=null){
//set default location
$query = "update `users` set `locid`='2256755', `regid`='243', `ccid`='12' where `id`='".$id."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
//clear listings
$query = "update `users` set `listme`=' ',`contactinfo`=' ' where `id`='".$id."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
//set lanuage to default
//set default language
- mysqli_query($_SESSION['mconn'], "update `users` set `language`='en_AU' where `id`='".$id."'");
+ mysql_query("update `users` set `language`='en_AU' where `id`='".$id."'");
//delete secondary langugaes
- mysqli_query($_SESSION['mconn'], "delete from `addlang` where `userid`='".$id."'");
+ mysql_query("delete from `addlang` where `userid`='".$id."'");
//change secret questions
for($i=1;$i<=5;$i++){
@@ -1186,7 +1186,7 @@ function get_user_agreements($memid, $type=null, $active=null){
$a .= substr($pool,(rand()%(strlen ($pool))), 1);
}
$query = "update `users` set `Q$i`='$q', `A$i`='$a' where `id`='".$id."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
}
//change personal information to arbitration number and DOB=1900-01-01
@@ -1196,10 +1196,10 @@ function get_user_agreements($memid, $type=null, $active=null){
`suffix`='".$arbno."',
`dob`='1900-01-01'
where `id`='".$id."'";
- mysqli_query($_SESSION['mconn'], $query);
+ mysql_query($query);
//clear all admin and board flags
- mmysqli_query($_SESSION['mconn'],
+ mysql_query(
"update `users` set
`assurer`='0',
`assurer_blocked`='0',
@@ -1214,17 +1214,17 @@ function get_user_agreements($memid, $type=null, $active=null){
where `id`='$id'");
//block account
- mysqli_query($_SESSION['mconn'], "update `users` set `locked`='1' where `id`='$id'"); //, `deleted`=Now()
+ mysql_query("update `users` set `locked`='1' where `id`='$id'"); //, `deleted`=Now()
}
function check_email_exists($email){
// called from includes/account.php if($process != "" && $oldid == 1)
// called from includes/account.php if($oldid == 50 && $process != "")
- $email = mysqli_real_escape_string($_SESSION['mconn'], $email);
+ $email = mysql_real_escape_string($email);
$query = "select 1 from `email` where `email`='$email' and `deleted`=0";
- $res = mysqli_query($_SESSION['mconn'], $query);
- return mysqli_num_rows($res) > 0;
+ $res = mysql_query($query);
+ return mysql_num_rows($res) > 0;
}
function check_gpg_cert_running($uid,$cca=0){
@@ -1236,8 +1236,8 @@ function get_user_agreements($memid, $type=null, $active=null){
}else{
$query = "select 1 from `gpg` where `memid`='$uid' and `expire`>(NOW()-90*86400)";
}
- $res = mysqli_query($_SESSION['mconn'], $query);
- return mysqli_num_rows($res) > 0;
+ $res = mysql_query($query);
+ return mysql_num_rows($res) > 0;
}
function check_client_cert_running($uid,$cca=0){
@@ -1251,10 +1251,10 @@ function get_user_agreements($memid, $type=null, $active=null){
$query1 = "select 1 from `emailcerts` where `memid`='$uid' and `expire`>(NOW()-90*86400) and `revoked`<`created`";
$query2 = "select 1 from `emailcerts` where `memid`='$uid' and `revoked`>(NOW()-90*86400)";
}
- $res = mysqli_query($_SESSION['mconn'], $query1);
- $r1 = mysqli_num_rows($res)>0;
- $res = mysqli_query($_SESSION['mconn'], $query2);
- $r2 = mysqli_num_rows($res)>0;
+ $res = mysql_query($query1);
+ $r1 = mysql_num_rows($res)>0;
+ $res = mysql_query($query2);
+ $r2 = mysql_num_rows($res)>0;
return !!($r1 || $r2);
}
@@ -1287,10 +1287,10 @@ function get_user_agreements($memid, $type=null, $active=null){
where `domains`.`memid` = '$uid'
and `revoked`>(NOW()-90*86400)";
}
- $res = mysqli_query($_SESSION['mconn'], $query1);
- $r1 = mysqli_num_rows($res)>0;
- $res = mysqli_query($_SESSION['mconn'], $query2);
- $r2 = mysqli_num_rows($res)>0;
+ $res = mysql_query($query1);
+ $r1 = mysql_num_rows($res)>0;
+ $res = mysql_query($query2);
+ $r2 = mysql_num_rows($res)>0;
return !!($r1 || $r2);
}
@@ -1298,8 +1298,8 @@ function get_user_agreements($memid, $type=null, $active=null){
// called from includes/account.php if($oldid == 50 && $process != "")
$uid = intval($uid);
$query = "select 1 from `org` where `memid`='$uid' and `deleted`=0";
- $res = mysqli_query($_SESSION['mconn'], $query);
- return mysqli_num_rows($res) > 0;
+ $res = mysql_query($query);
+ return mysql_num_rows($res) > 0;
}
@@ -1311,9 +1311,9 @@ function get_user_agreements($memid, $type=null, $active=null){
from `emaillink`,`emailcerts` where
`emaillink`.`emailid`='$mailid' and `emaillink`.`emailcertsid`=`emailcerts`.`id` and `emailcerts`.`revoked`=0
group by `emailcerts`.`id`";
- $dres = mysqli_query($_SESSION['mconn'], $query);
- while($drow = mysqli_fetch_assoc($dres)){
- mysqli_query($_SESSION['mconn'], "update `emailcerts` set `revoked`='1970-01-01 10:00:01', `disablelogin`=1 where `id`='".$drow['id']."'");
+ $dres = mysql_query($query);
+ while($drow = mysql_fetch_assoc($dres)){
+ mysql_query("update `emailcerts` set `revoked`='1970-01-01 10:00:01', `disablelogin`=1 where `id`='".$drow['id']."'");
}
}
@@ -1329,10 +1329,10 @@ function get_user_agreements($memid, $type=null, $active=null){
from `domaincerts`, `domlink`
where `domaincerts`.`id` = `domlink`.`certid`
and `domlink`.`domid` = '$domainid'";
- $dres = mysqli_query($_SESSION['mconn'], $query);
- while($drow = mysqli_fetch_assoc($dres))
+ $dres = mysql_query($query);
+ while($drow = mysql_fetch_assoc($dres))
{
- mysqli_query($_SESSION['mconn'],
+ mysql_query(
"update `domaincerts`
set `revoked`='1970-01-01 10:00:01'
where `id` = '".$drow['id']."'
@@ -1345,15 +1345,15 @@ function get_user_agreements($memid, $type=null, $active=null){
//gpg revokation needs to be added to a later point
$uid=intval($uid);
$query = "select `id` from `email` where `memid`='".$uid."'";
- $res=mysqli_query($_SESSION['mconn'], $query);
- while($row = mysqli_fetch_assoc($res)){
+ $res=mysql_query($query);
+ while($row = mysql_fetch_assoc($res)){
revoke_all_client_cert($row['id']);
}
$query = "select `id` from `domains` where `memid`='".$uid."'";
- $res=mysqli_query($_SESSION['mconn'], $query);
- while($row = mysqli_fetch_assoc($res)){
+ $res=mysql_query($query);
+ while($row = mysql_fetch_assoc($res)){
revoke_all_server_cert($row['id']);
}
}
@@ -1415,11 +1415,11 @@ function write_se_log($uid, $adminid, $type, $info){
//records all support engineer actions changing a user account
$uid = intval($uid);
$adminid = intval($adminid);
- $type = mysqli_real_escape_string($_SESSION['mconn'], $type);
- $info = mysqli_real_escape_string($_SESSION['mconn'], g($info);
+ $type = mysql_real_escape_string($type);
+ $info = mysql_real_escape_string($info);
$query="insert into `adminlog` (`when`, `uid`, `adminid`,`type`,`information`) values
(Now(), $uid, $adminid, '$type', '$info')";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1453,7 +1453,7 @@ function get_user_data($userid, $deleted=0){
$filter .=' and `users`.`deleted`=0';
}
$query = "select * from `users` where `users`.`id`='$userid' ".$filter;
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1462,7 +1462,7 @@ function get_user_data($userid, $deleted=0){
* @return array - associative array
*/
function get_alerts($userid){
- return mysqli_fetch_assoc(mysqli_query($_SESSION['mconn'], "select * from `alerts` where `memid`='".intval($userid)."'"));
+ return mysql_fetch_assoc(mysql_query("select * from `alerts` where `memid`='".intval($userid)."'"));
}
/**
@@ -1480,10 +1480,10 @@ function get_email_addresses($userid, $exclude, $deleted=0){
$filter .= ' and `deleted`=0';
}
if ($exclude) {
- $filter .= " and `email`!='".mysqli_real_escape_string($_SESSION['mconn'], $exclude)."'";
+ $filter .= " and `email`!='".mysql_real_escape_string($exclude)."'";
}
$query = "select * from `email` where `memid`='".$userid."' and `hash`='' ".$filter." order by `created`";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1500,7 +1500,7 @@ function get_domains($userid, $deleted=0){
$filter .= ' and `deleted`=0';
}
$query = "select * from `domains` where `memid`='".$userid."' and `hash`=''".$filter." order by `created`";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1515,7 +1515,7 @@ function get_training_results($userid){
" FROM `cats_passed` AS CP, `cats_variant` AS CV, `cats_type` AS CT ".
" WHERE `CP`.`variant_id`=`CV`.`id` AND `CV`.`type_id`=`CT`.`id` AND `CP`.`user_id` ='".$userid."'".
" ORDER BY `CP`.`pass_date`";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1529,7 +1529,7 @@ function get_se_log($userid){
FROM `adminlog`, `users`
WHERE `adminlog`.`adminid` = `users`.`id` and `adminlog`.`uid`=".$userid."
ORDER BY `adminlog`.`when`";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1560,7 +1560,7 @@ function get_client_certs($userid, $viewall=0){
$query .= " HAVING `timeleft` > 0";
}
$query .= " ORDER BY `emailcerts`.`modified` desc";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1590,7 +1590,7 @@ function get_server_certs($userid, $viewall=0){
$query .= " HAVING `timeleft` > 0";
}
$query .= " ORDER BY `domaincerts`.`modified` desc";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
/**
@@ -1611,7 +1611,7 @@ function get_gpg_certs($userid, $viewall=0){
$query .= " HAVING `timeleft` > 0";
}
$query .= " ORDER BY `issued` desc";
- return mysqli_query($_SESSION['mconn'], $query);
+ return mysql_query($query);
}
diff --git a/pages/account/12.php b/pages/account/12.php
index 234891f..f4428aa 100644
--- a/pages/account/12.php
+++ b/pages/account/12.php
@@ -49,15 +49,15 @@
}
$query .= "ORDER BY `modified` desc";
//echo $query."| =sanitizeHTML($row['domain'])?> | diff --git a/pages/account/27.php b/pages/account/27.php index 7c73be4..a1086d4 100644 --- a/pages/account/27.php +++ b/pages/account/27.php @@ -16,7 +16,7 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA */ ?> - $row = mysqli_fetch_assoc(mysql_query("select * from `orginfo` where `id`='".intval($_REQUEST['orgid'])."'")); + $row = mysql_fetch_assoc(mysql_query("select * from `orginfo` where `id`='".intval($_REQUEST['orgid'])."'")); ?>