This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | |||
3 | /** |
||
4 | * |
||
5 | * Module: SmartPartner |
||
6 | * Author: The SmartFactory <www.smartfactory.ca> |
||
7 | * Licence: GNU |
||
8 | */ |
||
9 | |||
10 | include __DIR__ . '/header.php'; |
||
11 | $xoopsOption['template_main'] = 'smartpartner_join.tpl'; |
||
12 | include XOOPS_ROOT_PATH . '/header.php'; |
||
13 | include __DIR__ . '/footer.php'; |
||
14 | |||
15 | $myts = MyTextSanitizer::getInstance(); |
||
16 | |||
17 | $op = isset($_POST['op']) ? $_POST['op'] : 'form'; |
||
18 | |||
19 | switch ($op) { |
||
20 | |||
21 | case 'submitPartner': |
||
22 | include XOOPS_ROOT_PATH . '/class/xoopsmailer.php'; |
||
23 | |||
24 | $partnerObj = $smartPartnerPartnerHandler->create(); |
||
25 | // Uploading the logo, if any |
||
26 | // Retreive the filename to be uploaded |
||
27 | |||
28 | if ($_FILES['logo_file']['name'] !== '') { |
||
29 | $filename = $_POST['xoops_upload_file'][0]; |
||
30 | View Code Duplication | if (!empty($filename) || $filename !== '') { |
|
31 | global $xoopsModuleConfig; |
||
0 ignored issues
–
show
|
|||
32 | |||
33 | $max_size = 10000000; |
||
34 | $max_imgwidth = $xoopsModuleConfig['img_max_width']; |
||
35 | $max_imgheight = $xoopsModuleConfig['img_max_height']; |
||
36 | $allowed_mimetypes = smartpartner_getAllowedImagesTypes(); |
||
37 | |||
38 | include_once(XOOPS_ROOT_PATH . '/class/uploader.php'); |
||
39 | |||
40 | if ($_FILES[$filename]['tmp_name'] === '' || !is_readable($_FILES[$filename]['tmp_name'])) { |
||
41 | redirect_header('javascript:history.go(-1)', 2, _CO_SPARTNER_FILE_UPLOAD_ERROR); |
||
42 | exit; |
||
43 | } |
||
44 | |||
45 | $uploader = new XoopsMediaUploader(smartpartner_getImageDir(), $allowed_mimetypes, $max_size, $max_imgwidth, $max_imgheight); |
||
46 | |||
47 | if ($uploader->fetchMedia($filename) && $uploader->upload()) { |
||
48 | $partnerObj->setVar('image', $uploader->getSavedFileName()); |
||
49 | } else { |
||
50 | redirect_header('javascript:history.go(-1)', 2, _CO_SPARTNER_FILE_UPLOAD_ERROR . $uploader->getErrors()); |
||
51 | exit; |
||
52 | } |
||
53 | } |
||
54 | } |
||
55 | |||
56 | // Putting the values in the partner object |
||
57 | $partnerObj->setVar('id', isset($_POST['id']) ? (int)$_POST['id'] : 0); |
||
58 | $partnerObj->setVar('title', $_POST['title']); |
||
59 | $partnerObj->setVar('summary', $_POST['summary']); |
||
60 | $partnerObj->setVar('description', $_POST['description']); |
||
61 | $partnerObj->setVar('contact_name', $_POST['contact_name']); |
||
62 | $partnerObj->setVar('contact_email', $_POST['contact_email']); |
||
63 | $partnerObj->setVar('contact_phone', $_POST['contact_phone']); |
||
64 | $partnerObj->setVar('adress', $_POST['adress']); |
||
65 | $partnerObj->setVar('url', $_POST['url']); |
||
66 | $partnerObj->setVar('image_url', $_POST['image_url']); |
||
67 | $partnerObj->setVar('weight', isset($_POST['weight']) ? (int)$_POST['weight'] : 0); |
||
68 | $partnerObj->setVar('status', _SPARTNER_STATUS_SUBMITTED); |
||
69 | $partnerObj->setVar('email_priv', isset($_POST['email_priv']) ? (int)$_POST['email_priv'] : 0); |
||
70 | $partnerObj->setVar('phone_priv', isset($_POST['phone_priv']) ? (int)$_POST['phone_priv'] : 0); |
||
71 | $partnerObj->setVar('adress_priv', isset($_POST['adress_priv']) ? (int)$_POST['adress_priv'] : 0); |
||
72 | |||
73 | if ($xoopsModuleConfig['autoapprove_submitted']) { |
||
74 | $partnerObj->setVar('status', _SPARTNER_STATUS_ACTIVE); |
||
75 | } else { |
||
76 | $partnerObj->setVar('status', _SPARTNER_STATUS_SUBMITTED); |
||
77 | } |
||
78 | |||
79 | // Storing the partner |
||
80 | View Code Duplication | if (!$partnerObj->store()) { |
|
81 | redirect_header('javascript:history.go(-1)', 3, _MD_SPARTNER_SUBMIT_ERROR . smartpartner_formatErrors($partnerObj->getErrors())); |
||
82 | exit; |
||
83 | } |
||
84 | |||
85 | if (isset($_POST['notifypub']) && $_POST['notifypub'] === 1) { |
||
86 | include_once XOOPS_ROOT_PATH . '/include/notification_constants.php'; |
||
87 | $notificationHandler = xoops_getHandler('notification'); |
||
88 | $notificationHandler->subscribe('partner', $partnerObj->id(), 'approved', XOOPS_NOTIFICATION_MODE_SENDONCETHENDELETE); |
||
89 | } |
||
90 | |||
91 | $partnerObj->sendNotifications(array(_SPARTNER_NOT_PARTNER_SUBMITTED)); |
||
92 | redirect_header('index.php', 3, _MD_SPARTNER_SUBMIT_SUCCESS); |
||
93 | exit; |
||
94 | break; |
||
95 | |||
96 | case 'form': |
||
97 | if (($xoopsModuleConfig['allowsubmit'] !== 1) || (!$xoopsUser) && $xoopsModuleConfig['anonpost'] !== 1) { |
||
98 | redirect_header('index.php', 2, _NOPERM); |
||
99 | } |
||
100 | |||
101 | include XOOPS_ROOT_PATH . '/class/xoopsformloader.php'; |
||
102 | include XOOPS_ROOT_PATH . '/modules/smartobject/class/form/elements/smartformhidden.php'; |
||
103 | $form = new XoopsThemeForm(_MD_SPARTNER_JOIN, 'joinform', 'join.php'); |
||
104 | $form->setExtra('enctype="multipart/form-data"'); |
||
105 | |||
106 | // TITLE |
||
107 | $title_text = new XoopsFormText(_CO_SPARTNER_TITLE, 'title', 50, 255, ''); |
||
108 | $title_text->setDescription(_CO_SPARTNER_TITLE_DSC); |
||
109 | $form->addElement($title_text, true); |
||
110 | |||
111 | // LOGO UPLOAD |
||
112 | $max_size = 5000000; |
||
113 | $file_box = new XoopsFormFile(_CO_SPARTNER_LOGO_UPLOAD, 'logo_file', $max_size); |
||
114 | $file_box->setExtra("size ='45'"); |
||
115 | $file_box->setDescription(sprintf(_CO_SPARTNER_LOGO_UPLOAD_DSC, $xoopsModuleConfig['img_max_width'], $xoopsModuleConfig['img_max_height'])); |
||
116 | $form->addElement($file_box); |
||
117 | |||
118 | // IMAGE_URL |
||
119 | $image_url_text = new XoopsFormText(_CO_SPARTNER_IMAGE_URL, 'image_url', 50, 255, ''); |
||
120 | $image_url_text->setDescription(_CO_SPARTNER_IMAGE_URL_DSC); |
||
121 | $form->addElement($image_url_text, false); |
||
122 | |||
123 | // URL |
||
124 | $url_text = new XoopsFormText(_CO_SPARTNER_URL, 'url', 50, 255, ''); |
||
125 | $url_text->setDescription(_CO_SPARTNER_URL_DSC); |
||
126 | $form->addElement($url_text, false); |
||
127 | |||
128 | // SUMMARY |
||
129 | $summary_text = new XoopsFormTextArea(_CO_SPARTNER_SUMMARY, 'summary', '', 7, 60); |
||
130 | $summary_text->setDescription(_CO_SPARTNER_SUMMARY_DSC); |
||
131 | $form->addElement($summary_text, true); |
||
132 | |||
133 | // DESCRIPTION |
||
134 | $description_text = new XoopsFormDhtmlTextArea(_CO_SPARTNER_DESCRIPTION, 'description', '', 15, 60); |
||
135 | $description_text->setDescription(_CO_SPARTNER_DESCRIPTION_DSC); |
||
136 | $form->addElement($description_text, false); |
||
137 | |||
138 | // CONTACT_NAME |
||
139 | $contact_name_text = new XoopsFormText(_CO_SPARTNER_CONTACT_NAME, 'contact_name', 50, 255, ''); |
||
140 | $contact_name_text->setDescription(_CO_SPARTNER_CONTACT_NAME_DSC); |
||
141 | $form->addElement($contact_name_text, false); |
||
142 | |||
143 | // CONTACT_EMAIL |
||
144 | $contact_email_text = new XoopsFormText(_CO_SPARTNER_CONTACT_EMAIL, 'contact_email', 50, 255, ''); |
||
145 | $contact_email_text->setDescription(_CO_SPARTNER_CONTACT_EMAIL_DSC); |
||
146 | $form->addElement($contact_email_text, false); |
||
147 | |||
148 | // EMAIL_PRIV |
||
149 | $email_priv_radio = new XoopsFormRadioYN(_CO_SPARTNER_CONTACT_EMAILPRIV, 'email_priv', 0); |
||
150 | $email_priv_radio->setDescription(_CO_SPARTNER_CONTACT_EMAILPRIV_DSC); |
||
151 | $form->addElement($email_priv_radio); |
||
152 | |||
153 | // CONTACT_PHONE |
||
154 | $contact_phone_text = new XoopsFormText(_CO_SPARTNER_CONTACT_PHONE, 'contact_phone', 50, 255, ''); |
||
155 | $contact_phone_text->setDescription(_CO_SPARTNER_CONTACT_PHONE_DSC); |
||
156 | $form->addElement($contact_phone_text, false); |
||
157 | |||
158 | // PHONE_PRIV |
||
159 | $phone_priv_radio = new XoopsFormRadioYN(_CO_SPARTNER_CONTACT_PHONEPRIV, 'phone_priv', 0); |
||
160 | $phone_priv_radio->setDescription(_CO_SPARTNER_CONTACT_PHONEPRIV_DSC); |
||
161 | $form->addElement($phone_priv_radio); |
||
162 | |||
163 | // ADRESS |
||
164 | $adress_text = new XoopsFormTextArea(_CO_SPARTNER_ADRESS, 'adress', '', 4, 60); |
||
165 | $adress_text->setDescription(_CO_SPARTNER_ADRESS_DSC); |
||
166 | $form->addElement($adress_text, false); |
||
167 | |||
168 | // ADRESS_PRIV |
||
169 | $adress_priv_radio = new XoopsFormRadioYN(_CO_SPARTNER_CONTACT_ADRESSPRIV, 'adress_priv', 0); |
||
170 | $adress_priv_radio->setDescription(_CO_SPARTNER_CONTACT_ADRESSPRIV_DSC); |
||
171 | $form->addElement($adress_priv_radio); |
||
172 | |||
173 | // NOTIFY ON PUBLISH |
||
174 | if (is_object($xoopsUser) && ($xoopsModuleConfig['autoapprove_submitted'] != 1)) { |
||
175 | $notify_checkbox = new XoopsFormCheckBox('', 'notifypub', 1); |
||
176 | $notify_checkbox->addOption(1, _MD_SPARTNER_NOTIFY); |
||
177 | $form->addElement($notify_checkbox); |
||
178 | } |
||
179 | $form->addElement(new SmartFormHidden('partial_view', $xoopsModuleConfig['default_part_view'])); |
||
180 | $form->addElement(new SmartFormHidden('full_view', $xoopsModuleConfig['default_full_view'])); |
||
181 | |||
182 | // BUTTONS |
||
183 | $button_tray = new XoopsFormElementTray('', ''); |
||
184 | $hidden = new XoopsFormHidden('op', 'submitPartner'); |
||
185 | $button_tray->addElement($hidden); |
||
186 | |||
187 | $butt_create = new XoopsFormButton('', '', _CO_SPARTNER_SUBMIT, 'submit'); |
||
188 | $butt_create->setExtra('onclick="this.form.elements.op.value=\'submitPartner\'"'); |
||
189 | $button_tray->addElement($butt_create); |
||
190 | |||
191 | $butt_clear = new XoopsFormButton('', '', _CO_SPARTNER_CLEAR, 'reset'); |
||
192 | $button_tray->addElement($butt_clear); |
||
193 | |||
194 | $butt_cancel = new XoopsFormButton('', '', _CO_SPARTNER_CANCEL, 'button'); |
||
195 | $butt_cancel->setExtra('onclick="history.go(-1)"'); |
||
196 | $button_tray->addElement($butt_cancel); |
||
197 | |||
198 | $form->addElement($button_tray, true); |
||
199 | |||
200 | $form->assign($xoopsTpl); |
||
201 | $xoopsTpl->assign(array('lang_main_partner' => _MD_SPARTNER_PARTNERS, 'lang_join' => _MD_SPARTNER_JOIN)); |
||
202 | $xoopsTpl->assign('lang_intro_title', _MD_SPARTNER_JOIN); |
||
203 | $xoopsTpl->assign('lang_intro_text', sprintf(_MD_SPARTNER_INTRO_JOIN, $xoopsConfig['sitename'])); |
||
204 | $xoopsTpl->assign('xoops_pagetitle', $myts->htmlSpecialChars($xoopsModule->name()) . ' - ' . _MD_SPARTNER_JOIN); |
||
205 | break; |
||
206 | } |
||
207 | include_once XOOPS_ROOT_PATH . '/footer.php'; |
||
208 |
Instead of relying on
global
state, we recommend one of these alternatives:1. Pass all data via parameters
2. Create a class that maintains your state