Ignore:
Timestamp:
Feb 9, 2019, 8:45:24 PM (6 years ago)
Author:
roby
Message:
 
File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/admin/modules/Elezioni/ele_come.php

    r246 r257  
    1414    die ("You can't access this file directly...");
    1515}
    16 
     16global $dbi;
    1717$aid=$_SESSION['aid'];
    18 $dbi=$_SESSION['dbi'];
    1918$prefix=$_SESSION['prefix'];
    2019$currentlang=$_SESSION['lang'];
     
    3837/*********************************************************/
    3938$sql="SELECT t1.descrizione,t1.tipo_cons,t2.id_cons FROM ".$prefix."_ele_consultazione as t1, ".$prefix."_ele_cons_comune as t2 where t1.id_cons_gen=t2.id_cons_gen and t2.id_cons_gen='$id_cons_gen' and t2.id_comune='$id_comune'";
    40 $res = mysql_query("$sql", $dbi);
    41 list($descr_cons,$tipo_cons,$id_cons) = mysql_fetch_row($res);
     39$res = $dbi->prepare("$sql");
     40$res->execute();       
     41list($descr_cons,$tipo_cons,$id_cons) = $res->fetch(PDO::FETCH_NUM);
    4242
    4343include("modules/Elezioni/ele.php");
     
    6464
    6565
    66     $result = mysql_query("select  mid, title,preamble, content,  editimage from ".$prefix.$tab."  where id_cons='$id_cons'", $dbi);
    67     while(list($mid2, $title, $preamble, $content,  $editimage) = mysql_fetch_row($result)) {
     66    $sql="select  mid, title,preamble, content,  editimage from ".$prefix.$tab."  where id_cons='$id_cons'";
     67        $result = $dbi->prepare("$sql");
     68        $result->execute();     
     69    while(list($mid2, $title, $preamble, $content,  $editimage) = $result->fetch(PDO::FETCH_NUM)) {
    6870
    6971        echo "<tr>"
     
    8082    echo "<br>";
    8183    if($vai=='editedit'){
    82     $result = mysql_query("select title, preamble,content, editimage from ".$prefix.$tab." WHERE mid='$mid' AND id_cons='$id_cons'", $dbi);
    83     list($add_title,$add_preamble, $add_content, $editimage) = mysql_fetch_row($result);
     84    $sql="select title, preamble,content, editimage from ".$prefix.$tab." WHERE mid='$mid' AND id_cons='$id_cons'";
     85        $result = $dbi->prepare("$sql");
     86        $result->execute();     
     87    list($add_title,$add_preamble, $add_content, $editimage) = $result->fetch(PDO::FETCH_NUM);
    8488    }
    8589//25.05.2009
    8690    $sql="SELECT editor,ed_user FROM ".$prefix."_config";
    87 $res = mysql_query("$sql", $dbi);
    88 list($editor,$ed_user) = mysql_fetch_row($res);
     91        $res = $dbi->prepare("$sql");
     92        $res->execute();       
     93        list($editor,$ed_user) = $res->fetch(PDO::FETCH_NUM);
    8994//
    9095
     
    157162$temp=$title.$preamble.$content;
    158163        if (preg_match("/script/i",$temp)) die("La parola script e' proibita, devi toglierla dal testo.");
    159     $result = mysql_query("update ".$prefix.$tab." set title='$title', preamble='$preamble', content='$content' WHERE mid='$mid' AND id_cons='$id_cons'", $dbi);
     164    $sql="update ".$prefix.$tab." set title='$title', preamble='$preamble', content='$content' WHERE mid='$mid' AND id_cons='$id_cons'";
     165        $res = $dbi->prepare("$sql");
     166        $res->execute();       
    160167    Header("Location: admin.php?op=$op&vai=come&id_cons_gen=$id_cons_gen");
    161168}
     
    164171    global $prefix, $dbi,$id_cons, $id_cons_gen,$tab,$op;
    165172
    166     $result = mysql_query("insert into ".$prefix.$tab." (id_cons,title,preamble,content) values ('$id_cons', '$add_title', '$add_preamble','$add_content')", $dbi);
    167     if (!$result) {
     173    $sql="insert into ".$prefix.$tab." (id_cons,title,preamble,content) values ('$id_cons', '$add_title', '$add_preamble','$add_content')";
     174        $res = $dbi->prepare("$sql");
     175        $res->execute();       
     176    if (!$res->rowCount()) {
    168177        exit();
    169178    }
     
    175184    global $prefix, $dbi, $id_cons,$id_cons_gen,$tab,$op;
    176185    if($ok) {
    177         $result = mysql_query("delete from ".$prefix.$tab." where mid=$mid and id_cons='$id_cons'", $dbi);
    178         if (!$result) {
     186        $sql="delete from ".$prefix.$tab." where mid=$mid and id_cons='$id_cons'";
     187        $res = $dbi->prepare("$sql");
     188        $res->execute();       
     189        if (!$res->rowCount()) {
    179190            return;
    180191        }
Note: See TracChangeset for help on using the changeset viewer.