[ticket/11201] Cast some variables to integer

PHPBB3-11201
This commit is contained in:
Joas Schilling 2014-01-18 12:40:12 +01:00
parent 431fa7b593
commit 876e5e5fbb
2 changed files with 9 additions and 9 deletions

View file

@ -70,9 +70,9 @@ class lang_helper
else else
{ {
$sql = 'SELECT option_id, lang_value $sql = 'SELECT option_id, lang_value
FROM ' . $this->language_table . " FROM ' . $this->language_table . '
WHERE field_id = $field_id WHERE field_id = ' . (int) $field_id . '
AND lang_id = $lang_id AND lang_id = ' . (int) $lang_id . "
AND field_type = '" . $this->db->sql_escape($field_type) . "' AND field_type = '" . $this->db->sql_escape($field_type) . "'
ORDER BY option_id"; ORDER BY option_id";
$result = $this->db->sql_query($sql); $result = $this->db->sql_query($sql);

View file

@ -79,9 +79,9 @@ class profilefields
FROM ' . $this->fields_language_table . ' l, ' . $this->fields_table . " f FROM ' . $this->fields_language_table . ' l, ' . $this->fields_table . " f
WHERE f.field_active = 1 WHERE f.field_active = 1
$sql_where $sql_where
AND l.lang_id = $lang_id AND l.lang_id = " . (int) $lang_id . '
AND l.field_id = f.field_id AND l.field_id = f.field_id
ORDER BY f.field_order"; ORDER BY f.field_order';
$result = $this->db->sql_query($sql); $result = $this->db->sql_query($sql);
while ($row = $this->db->sql_fetchrow($result)) while ($row = $this->db->sql_fetchrow($result))
@ -153,8 +153,8 @@ class profilefields
} }
$sql = 'SELECT l.*, f.* $sql = 'SELECT l.*, f.*
FROM ' . $this->fields_language_table . ' l, ' . $this->fields_table . " f FROM ' . $this->fields_language_table . ' l, ' . $this->fields_table . ' f
WHERE l.lang_id = $lang_id WHERE l.lang_id = ' . (int) $lang_id . "
AND f.field_active = 1 AND f.field_active = 1
$sql_where $sql_where
AND l.field_id = f.field_id AND l.field_id = f.field_id
@ -218,8 +218,8 @@ class profilefields
} }
$sql = 'UPDATE ' . $this->fields_data_table . ' $sql = 'UPDATE ' . $this->fields_data_table . '
SET ' . $this->db->sql_build_array('UPDATE', $cp_data_sql) . " SET ' . $this->db->sql_build_array('UPDATE', $cp_data_sql) . '
WHERE user_id = $user_id"; WHERE user_id = ' . (int) $user_id;
$this->db->sql_query($sql); $this->db->sql_query($sql);
if (!$this->db->sql_affectedrows()) if (!$this->db->sql_affectedrows())