Skip to content
This repository has been archived by the owner on Jan 20, 2018. It is now read-only.

Commit

Permalink
Fixes #5
Browse files Browse the repository at this point in the history
  • Loading branch information
turtles2 committed Mar 15, 2016
1 parent c77e7fd commit f8a2183
Show file tree
Hide file tree
Showing 65 changed files with 250 additions and 174 deletions.
10 changes: 5 additions & 5 deletions activatecustomer2.php
Original file line number Diff line number Diff line change
Expand Up @@ -60,11 +60,11 @@
// do nothing
} // end if

$emailc = $mysqli->real_escape_string($email);
$phonec = $mysqli->real_escape_string($phone);
$l4c = $mysqli->real_escape_string($l4);
$plan = $mysqli->real_escape_string($plan);
$mode = $mysqli->real_escape_string($mode);
$emailc = inputcleaner($email,$mysqli);
$phonec = inputcleaner($phone,$mysqli);
$l4c = inputcleaner($l4,$mysqli);
$plan = inputcleaner($plan,$mysqli);
$mode = inputcleaner($mode,$mysqli);
if(!filter_var($emailc, FILTER_VALIDATE_EMAIL)){
$_SESSION['exitcodev2'] = 'email';
header('Location: activatecustomer.php');
Expand Down
12 changes: 5 additions & 7 deletions adddhcp2.php
Original file line number Diff line number Diff line change
Expand Up @@ -61,13 +61,11 @@
$_SESSION['exitcodev2'] = '';
}


$name = $mysqli->real_escape_string($name);
$pool = $mysqli->real_escape_string($pool);
$dns = $mysqli->real_escape_string($dns);
$site = $mysqli->real_escape_string($site);
$portid = $mysqli->real_escape_string($port);

$name = inputcleaner($name,$mysqli);
$pool = inputcleaner($pool,$mysqli);
$dns = inputcleaner($dns,$mysqli);
$site = inputcleaner($site,$mysqli);
$portid = inputcleaner($port,$mysqli);
// end of data sanitize and existence check
// start of data entry
if ($result2 = $mysqli->query("SELECT * FROM `devices` WHERE `type` = 'router'
Expand Down
10 changes: 5 additions & 5 deletions addlink2.php
Original file line number Diff line number Diff line change
Expand Up @@ -61,11 +61,11 @@
// do nothing
} // end if

$mastersite = $mysqli->real_escape_string($mastersite);
$masterport = $mysqli->real_escape_string($masterport);
$slavesite = $mysqli->real_escape_string($slavesite);
$slaveport = $mysqli->real_escape_string($slaveport);
$capacity = $mysqli->real_escape_string($capacity);
$mastersite = inputcleaner($mastersite,$mysqli);
$masterport = inputcleaner($masterport,$mysqli);
$slavesite = inputcleaner($slavesite,$mysqli);
$slaveport = inputcleaner($slaveport,$mysqli);
$capacity = inputcleaner($capacity,$mysqli);
// end of data sanitize and existence check
//start of data entry for system DB
if ($mysqli->query("INSERT INTO `$db`.`links` (`idlinks`, `capacity`, `status`, `master_site`, `slave_site`,
Expand Down
6 changes: 3 additions & 3 deletions assignticket2.php
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@

}

$assignto = $mysqli->real_escape_string($assignto);
$assignto = inputcleaner($assignto,$mysqli);

foreach ($_POST['id'] as $id) {
/*0 unassigned
Expand All @@ -50,8 +50,8 @@
*4 solved with escalation
Odd is unsloved and even is solved
*/
$id = $mysqli->real_escape_string($id);
$id = inputcleaner($id,$mysqli);

if ($result2 = $mysqli->query("SELECT * FROM `ticket` WHERE `idticket` = '$id'")) {
while ($row2 = $result2->fetch_assoc()) {
$cusinfoid= $row2["customer_info_idcustomer_info"];
Expand Down
8 changes: 5 additions & 3 deletions billcustomer2.php
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@
$email = $_POST["stripeEmail"];
$l4= $_POST["4"];
$token = $_POST['stripeToken'];

// end of post
// start of data sanitize and existence check
if (empty($email)) {
Expand All @@ -49,9 +50,10 @@
// do nothing
} // end if

$emailc = $mysqli->real_escape_string($email);
$phonec = $mysqli->real_escape_string($phone);
$l4c = $mysqli->real_escape_string($l4);
$emailc = inputcleaner($email,$mysqli);
$phonec = inputcleaner($phone,$mysqli);
$l4c = inputcleaner($l4,$mysqli);

if(!filter_var($emailc, FILTER_VALIDATE_EMAIL)){
$_SESSION['errorcode'] = 'email';
header('Location: billcustomer.php');
Expand Down
8 changes: 8 additions & 0 deletions billinglogic.php
Original file line number Diff line number Diff line change
Expand Up @@ -374,4 +374,12 @@ function mailuser($email,$event,$sendgridapi,$fromemail,$filldata) {
}
}// End of Mail User

function inputcleaner($input,$mysqli) {
// Other actions can go here
$input = $mysqli->real_escape_string($input);
$input = htmlspecialchars($input);

return $input;
}// inputcleaner

?>
7 changes: 4 additions & 3 deletions changecusser2.php
Original file line number Diff line number Diff line change
Expand Up @@ -49,9 +49,10 @@
// do nothing
} // end if

$emailc = $mysqli->real_escape_string($email);
$phonec = $mysqli->real_escape_string($phone);
$l4c = $mysqli->real_escape_string($l4);
$emailc = inputcleaner($email,$mysqli);
$phonec = inputcleaner($phone,$mysqli);
$l4c = inputcleaner($l4,$mysqli);

if(!filter_var($emailc, FILTER_VALIDATE_EMAIL)){
$_SESSION['exitcodev2'] = 'email';
header('Location: changecusser.php');
Expand Down
5 changes: 3 additions & 2 deletions closeticket2.php
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,9 @@
// Nothing
}

$id = $mysqli->real_escape_string($id);
$status= $mysqli->real_escape_string($status);

$id = inputcleaner($id,$mysqli);
$status = inputcleaner($status,$mysqli);

if(is_numeric($status)){
//nothing
Expand Down
9 changes: 4 additions & 5 deletions configrouter2.php
Original file line number Diff line number Diff line change
Expand Up @@ -56,11 +56,10 @@
}


$name = $mysqli->real_escape_string($name);
$pass = $mysqli->real_escape_string($pass);
$ip = $mysqli->real_escape_string($ip);
$router = $mysqli->real_escape_string($router);

$name = inputcleaner($name,$mysqli);
$pass = inputcleaner($pass,$mysqli);
$ip = inputcleaner($ip,$mysqli);
$router = inputcleaner($router,$mysqli);

// end of data sanitize and existence check
$routerip = $ip;
Expand Down
2 changes: 1 addition & 1 deletion configrouter3.php
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
$cleandata = $_SESSION['cleandata'];
// end of post

$router = $mysqli->real_escape_string($router);
$router = inputcleaner($router,$mysqli);

if ($result = $mysqli->query("SELECT * FROM `device_credentials` WHERE `devices_iddevices` = '$router'")) {
/* fetch associative array */
Expand Down
5 changes: 5 additions & 0 deletions configsite2.php
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,11 @@
} else{
// We are good
}

$id = inputcleaner($id,$mysqli);
$id2 = inputcleaner($id2,$mysqli);
$id3 = inputcleaner($id3,$mysqli);

if ($result = $mysqli->query("SELECT * FROM `devices` WHERE `iddevices` = $id")) {
/* fetch associative array */

Expand Down
4 changes: 4 additions & 0 deletions configsite3.php
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,10 @@
while ($row = $result2->fetch_assoc()) {
$port = $row["port_id"];
$use = $_POST["$port"];

$use = inputcleaner($use,$mysqli);


if ($result = $mysqli->query("INSERT INTO `$db`.`device_ports`
(`iddevice_ports`, `port id`, `use`,
`devices_iddevices`) VALUES
Expand Down
7 changes: 3 additions & 4 deletions convertlead2.php
Original file line number Diff line number Diff line change
Expand Up @@ -65,10 +65,9 @@
// do nothing
} // end if

$user = $mysqli->real_escape_string($user);
$pass1 = $mysqli->real_escape_string($pass1);
$pass2 = $mysqli->real_escape_string($pass2);

$user = inputcleaner($user,$mysqli);
$pass1 = inputcleaner($pass1,$mysqli);
$pass2 = inputcleaner($pass2,$mysqli);
// end of data sanitize and existence check
if ($result = $mysqli->query("SELECT * FROM `customer_info` WHERE `idcustomer_info` = $infoid")) {
/* fetch associative array */
Expand Down
4 changes: 2 additions & 2 deletions convertleadin2.php
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,8 @@
// Nothing
}

$leadid = $mysqli->real_escape_string($id);
$leadidid = inputcleaner($leadidid,$mysqli);

/*0 unassigned
*1 assigned but not solved
*2 assigned and solved
Expand Down
19 changes: 10 additions & 9 deletions createadminuser2.php
Original file line number Diff line number Diff line change
Expand Up @@ -86,15 +86,16 @@
} else{
// do nothing
} // end if
$fname = $mysqli->real_escape_string($fname);
$lname = $mysqli->real_escape_string($lname);
$tel = $mysqli->real_escape_string($tel);
$ctel = $mysqli->real_escape_string($ctel);
$user = $mysqli->real_escape_string($user);
$pass1 = $mysqli->real_escape_string($pass1);
$pass2 = $mysqli->real_escape_string($pass2);
$email1 = $mysqli->real_escape_string($email1);
$email2 = $mysqli->real_escape_string($email2);

$fname = inputcleaner($fname,$mysqli);
$lname = inputcleaner($lname,$mysqli);
$tel = inputcleaner($tel,$mysqli);
$ctel = inputcleaner($ctel,$mysqli);
$user = inputcleaner($user,$mysqli);
$pass1 = inputcleaner($pass1,$mysqli);
$pass2 = inputcleaner($pass2,$mysqli);
$email1 = inputcleaner($email1,$mysqli);
$email2 = inputcleaner($email2,$mysqli);

if(!filter_var($email1, FILTER_VALIDATE_EMAIL)){
$_SESSION['exitcode'] = 'email not valid';
Expand Down
21 changes: 11 additions & 10 deletions createcontact2.php
Original file line number Diff line number Diff line change
Expand Up @@ -22,16 +22,17 @@
require_once('./fileloader.php');
$mysqli = new mysqli("$ip", "$username", "$password", "$db");
// start of post
$fname = $_POST["fname"];
$lname = $_POST["lname"];
$org = $_POST["org"];
$tel = $_POST["tel"];
$add = $_POST["add"];
$city = $_POST["city"];
$zip = $_POST["zip"];
$state = $_POST["state"];
$email1 = $_POST["email"];
$email2 = $_POST["email2"];

$fname = inputcleaner($fname,$mysqli);
$lname = inputcleaner($lname,$mysqli);
$org = inputcleaner($org,$mysqli);
$tel = inputcleaner($tel,$mysqli);
$add = inputcleaner($add,$mysqli);
$city = inputcleaner($city,$mysqli);
$zip = inputcleaner($zip,$mysqli);
$state = inputcleaner($state,$mysqli);
$email1 = inputcleaner($email1,$mysqli);
$email2 = inputcleaner($email2,$mysqli);
// end of post

// start of data sanitize and existence check
Expand Down
4 changes: 4 additions & 0 deletions createcontactnote2.php
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,10 @@
// start of post
$note = $_POST["text1"];
$id = $_POST["contact"];

$id = inputcleaner($id,$mysqli);
$note = inputcleaner($note,$mysqli);

// end of post
// start of data sanitize and existence check
if (empty($note)) {
Expand Down
13 changes: 7 additions & 6 deletions createdevice2.php
Original file line number Diff line number Diff line change
Expand Up @@ -75,13 +75,14 @@
{
//do nothing
}
$name = $mysqli->real_escape_string($name);
$serial = $mysqli->real_escape_string($serial);
$modle = $mysqli->real_escape_string($modle);
$mac = $mysqli->real_escape_string($mac);
$type = $mysqli->real_escape_string($type);
$man = $mysqli->real_escape_string($man);


$name = inputcleaner($name,$mysqli);
$serial = inputcleaner($serial,$mysqli);
$modle = inputcleaner($modle,$mysqli);
$mac = inputcleaner($mac,$mysqli);
$type = inputcleaner($type,$mysqli);
$man = inputcleaner($man,$mysqli);
// end of data sanitize and existence check
// start of data entry
if ($mysqli->query("INSERT INTO `$db`.`devices` (`iddevices`, `location_idlocation`, `name`, `serial_number`, `manufacturer`, `model`, `type`, `librenms_id`, `field_status`, `mac`)
Expand Down
20 changes: 10 additions & 10 deletions createlead2.php
Original file line number Diff line number Diff line change
Expand Up @@ -91,17 +91,17 @@
// do nothing
} // end if

$fname = inputcleaner($fname,$mysqli);
$lname = inputcleaner($lname,$mysqli);
$tel = inputcleaner($tel,$mysqli);
$add = inputcleaner($add,$mysqli);
$city = inputcleaner($city,$mysqli);
$zip = inputcleaner($zip,$mysqli);
$state = inputcleaner($state,$mysqli);
$email1 = inputcleaner($email1,$mysqli);
$email2 = inputcleaner($email2,$mysqli);
$source = inputcleaner($source,$mysqli);

$fname = $mysqli->real_escape_string($fname);
$lname = $mysqli->real_escape_string($lname);
$tel = $mysqli->real_escape_string($tel);
$add = $mysqli->real_escape_string($add);
$city = $mysqli->real_escape_string($city);
$zip = $mysqli->real_escape_string($zip);
$state = $mysqli->real_escape_string($state);
$email1 = $mysqli->real_escape_string($email1);
$email2 = $mysqli->real_escape_string($email2);
$source = $mysqli->real_escape_string($source);
if(!filter_var($email1, FILTER_VALIDATE_EMAIL)){
$_SESSION['exitcodev2'] = 'Email was Not Valid';
header('Location: createlead.php');
Expand Down
4 changes: 4 additions & 0 deletions createplan2.php
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,10 @@
$up = $mysqli->real_escape_string($up);
$down = $mysqli->real_escape_string($down);

$name = inputcleaner($name,$mysqli);
$price = inputcleaner($price,$mysqli);
$up = inputcleaner($up,$mysqli);
$down = inputcleaner($down,$mysqli);
// end of data sanitize and existence check
// start of cheack for exsting plan name

Expand Down
12 changes: 5 additions & 7 deletions createsite2.php
Original file line number Diff line number Diff line change
Expand Up @@ -60,13 +60,11 @@
$_SESSION['exitcodev2'] = '';
}


$name = $mysqli->real_escape_string($name);
$lat = $mysqli->real_escape_string($lat);
$lon = $mysqli->real_escape_string($lon);
$type = $mysqli->real_escape_string($type);
$con = $mysqli->real_escape_string($con);

$name = inputcleaner($name,$mysqli);
$lat = inputcleaner($lat,$mysqli);
$lon = inputcleaner($lon,$mysqli);
$type = inputcleaner($type,$mysqli);
$con = inputcleaner($con,$mysqli);
// end of data sanitize and existence check
// start of data entry
if ($mysqli->query("INSERT INTO `$db`.`location` (`idlocation`, `name`,
Expand Down
5 changes: 2 additions & 3 deletions createticketnote2.php
Original file line number Diff line number Diff line change
Expand Up @@ -42,9 +42,8 @@
// do nothing
} // end if

$note = $mysqli->real_escape_string($note);
$id = $mysqli->real_escape_string($id);

$id = inputcleaner($id,$mysqli);
$note = inputcleaner($note,$mysqli);
// end of data sanitize and existence check

$time = time();
Expand Down
1 change: 1 addition & 0 deletions deleteadminuser2.php
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
}
$mysqli = new mysqli("$ip", "$username", "$password", "$db");
foreach ($_POST['id'] as $id) {
$id = inputcleaner($id,$mysqli);
if ($result = $mysqli->query("DELETE FROM `$db`.`admin_users` WHERE `admin_users`.`idadmin` = $id")) {

}
Expand Down
7 changes: 4 additions & 3 deletions deletecustomer2.php
Original file line number Diff line number Diff line change
Expand Up @@ -48,9 +48,10 @@
// do nothing
} // end if

$emailc = $mysqli->real_escape_string($email);
$phonec = $mysqli->real_escape_string($phone);
$l4c = $mysqli->real_escape_string($l4);
$emailc = inputcleaner($email,$mysqli);
$phonec = inputcleaner($phone,$mysqli);
$l4c = inputcleaner($l4,$mysqli);

if(!filter_var($emailc, FILTER_VALIDATE_EMAIL)){
$_SESSION['exitcodev2'] = 'email';
header('Location: deletecustomer.php');
Expand Down
2 changes: 2 additions & 0 deletions deletemail.php
Original file line number Diff line number Diff line change
Expand Up @@ -27,9 +27,11 @@
header('Location: index.php');
}
$folder = $_POST['folder'];
$folder = inputcleaner($folder,$mysqli);

if(isset($_POST['id'])){
$uid = $_POST['id'];
$uid = inputcleaner($uid,$mysqli);
} else{
//no folder we want to view
header('Location: mailbox.php');
Expand Down
Loading

0 comments on commit f8a2183

Please sign in to comment.