Changeset 257 for trunk/admin/modules/Elezioni/ele_come.php
- Timestamp:
- Feb 9, 2019, 8:45:24 PM (6 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/admin/modules/Elezioni/ele_come.php
r246 r257 14 14 die ("You can't access this file directly..."); 15 15 } 16 16 global $dbi; 17 17 $aid=$_SESSION['aid']; 18 $dbi=$_SESSION['dbi'];19 18 $prefix=$_SESSION['prefix']; 20 19 $currentlang=$_SESSION['lang']; … … 38 37 /*********************************************************/ 39 38 $sql="SELECT t1.descrizione,t1.tipo_cons,t2.id_cons FROM ".$prefix."_ele_consultazione as t1, ".$prefix."_ele_cons_comune as t2 where t1.id_cons_gen=t2.id_cons_gen and t2.id_cons_gen='$id_cons_gen' and t2.id_comune='$id_comune'"; 40 $res = mysql_query("$sql", $dbi); 41 list($descr_cons,$tipo_cons,$id_cons) = mysql_fetch_row($res); 39 $res = $dbi->prepare("$sql"); 40 $res->execute(); 41 list($descr_cons,$tipo_cons,$id_cons) = $res->fetch(PDO::FETCH_NUM); 42 42 43 43 include("modules/Elezioni/ele.php"); … … 64 64 65 65 66 $result = mysql_query("select mid, title,preamble, content, editimage from ".$prefix.$tab." where id_cons='$id_cons'", $dbi); 67 while(list($mid2, $title, $preamble, $content, $editimage) = mysql_fetch_row($result)) { 66 $sql="select mid, title,preamble, content, editimage from ".$prefix.$tab." where id_cons='$id_cons'"; 67 $result = $dbi->prepare("$sql"); 68 $result->execute(); 69 while(list($mid2, $title, $preamble, $content, $editimage) = $result->fetch(PDO::FETCH_NUM)) { 68 70 69 71 echo "<tr>" … … 80 82 echo "<br>"; 81 83 if($vai=='editedit'){ 82 $result = mysql_query("select title, preamble,content, editimage from ".$prefix.$tab." WHERE mid='$mid' AND id_cons='$id_cons'", $dbi); 83 list($add_title,$add_preamble, $add_content, $editimage) = mysql_fetch_row($result); 84 $sql="select title, preamble,content, editimage from ".$prefix.$tab." WHERE mid='$mid' AND id_cons='$id_cons'"; 85 $result = $dbi->prepare("$sql"); 86 $result->execute(); 87 list($add_title,$add_preamble, $add_content, $editimage) = $result->fetch(PDO::FETCH_NUM); 84 88 } 85 89 //25.05.2009 86 90 $sql="SELECT editor,ed_user FROM ".$prefix."_config"; 87 $res = mysql_query("$sql", $dbi); 88 list($editor,$ed_user) = mysql_fetch_row($res); 91 $res = $dbi->prepare("$sql"); 92 $res->execute(); 93 list($editor,$ed_user) = $res->fetch(PDO::FETCH_NUM); 89 94 // 90 95 … … 157 162 $temp=$title.$preamble.$content; 158 163 if (preg_match("/script/i",$temp)) die("La parola script e' proibita, devi toglierla dal testo."); 159 $result = mysql_query("update ".$prefix.$tab." set title='$title', preamble='$preamble', content='$content' WHERE mid='$mid' AND id_cons='$id_cons'", $dbi); 164 $sql="update ".$prefix.$tab." set title='$title', preamble='$preamble', content='$content' WHERE mid='$mid' AND id_cons='$id_cons'"; 165 $res = $dbi->prepare("$sql"); 166 $res->execute(); 160 167 Header("Location: admin.php?op=$op&vai=come&id_cons_gen=$id_cons_gen"); 161 168 } … … 164 171 global $prefix, $dbi,$id_cons, $id_cons_gen,$tab,$op; 165 172 166 $result = mysql_query("insert into ".$prefix.$tab." (id_cons,title,preamble,content) values ('$id_cons', '$add_title', '$add_preamble','$add_content')", $dbi); 167 if (!$result) { 173 $sql="insert into ".$prefix.$tab." (id_cons,title,preamble,content) values ('$id_cons', '$add_title', '$add_preamble','$add_content')"; 174 $res = $dbi->prepare("$sql"); 175 $res->execute(); 176 if (!$res->rowCount()) { 168 177 exit(); 169 178 } … … 175 184 global $prefix, $dbi, $id_cons,$id_cons_gen,$tab,$op; 176 185 if($ok) { 177 $result = mysql_query("delete from ".$prefix.$tab." where mid=$mid and id_cons='$id_cons'", $dbi); 178 if (!$result) { 186 $sql="delete from ".$prefix.$tab." where mid=$mid and id_cons='$id_cons'"; 187 $res = $dbi->prepare("$sql"); 188 $res->execute(); 189 if (!$res->rowCount()) { 179 190 return; 180 191 }
Note:
See TracChangeset
for help on using the changeset viewer.