This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
1 | <?php declare(strict_types=1); |
||
2 | /* |
||
3 | * You may not change or alter any portion of this comment or credits |
||
4 | * of supporting developers from this source code or any supporting source code |
||
5 | * which is considered copyrighted (c) material of the original comment or credit authors. |
||
6 | * |
||
7 | * This program is distributed in the hope that it will be useful, |
||
8 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
9 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
||
10 | */ |
||
11 | |||
12 | /** |
||
13 | * @copyright XOOPS Project (https://xoops.org) |
||
14 | * @license GNU GPL 2.0 or later (https://www.gnu.org/licenses/gpl-2.0.html) |
||
15 | * @author XOOPS Development Team |
||
16 | * @author Pascal Le Boustouller: original author ([email protected]) |
||
17 | * @author Luc Bizet (www.frxoops.org) |
||
18 | * @author jlm69 (www.jlmzone.com) |
||
19 | * @author mamba (www.xoops.org) |
||
20 | */ |
||
21 | |||
22 | use XoopsModules\Adslight\{ |
||
23 | Helper, |
||
24 | Utility |
||
25 | }; |
||
26 | |||
27 | /** @var Helper $helper */ |
||
28 | |||
29 | /** |
||
30 | * @param $options |
||
31 | * @return array|false |
||
32 | */ |
||
33 | function adslight_b2_show($options) |
||
34 | { |
||
35 | if (!class_exists(Helper::class)) { |
||
36 | return []; |
||
37 | } |
||
38 | |||
39 | $helper = Helper::getInstance(); |
||
40 | |||
41 | global $xoopsDB, $block_lang; |
||
42 | $block = []; |
||
43 | $myts = \MyTextSanitizer::getInstance(); |
||
0 ignored issues
–
show
Unused Code
introduced
by
![]() |
|||
44 | $moduleDirName = \basename(\dirname(__DIR__)); |
||
45 | $block_lang = '_MB_' . mb_strtoupper($moduleDirName); |
||
46 | $block['title'] = constant("{$block_lang}_TITLE"); |
||
47 | |||
48 | $updir = $helper->getConfig($moduleDirName . '_link_upload', ''); |
||
0 ignored issues
–
show
|
|||
49 | $cat_perms = ''; |
||
50 | $categories = Utility::getMyItemIds('adslight_view'); |
||
51 | if (is_array($categories) && count($categories) > 0) { |
||
52 | $cat_perms .= ' AND cid IN (' . implode(',', $categories) . ') '; |
||
53 | } |
||
54 | |||
55 | $sql = 'SELECT lid, cid, title, status, type, price, typeprice, date_created, town, country, contactby, usid, premium, valid, photo, hits FROM ' . $xoopsDB->prefix("{$moduleDirName}_listing") . " WHERE valid='Yes' AND status!='1' {$cat_perms} ORDER BY {$options[0]} DESC"; |
||
56 | $result = $xoopsDB->query($sql, $options[1], 0); |
||
57 | if (!$xoopsDB->isResultSet($result)) { |
||
58 | \trigger_error("Query Failed! SQL: $sql- Error: " . $xoopsDB->error(), E_USER_ERROR); |
||
59 | } |
||
60 | while (false !== ($myrow = $xoopsDB->fetchArray($result))) { |
||
61 | $a_item = []; |
||
62 | $title = \htmlspecialchars($myrow['title'], ENT_QUOTES | ENT_HTML5); |
||
63 | // $status = \htmlspecialchars($myrow['status']); |
||
64 | $status = (int)$myrow['status']; |
||
65 | $type = \htmlspecialchars($myrow['type'], ENT_QUOTES | ENT_HTML5); |
||
66 | $price = (float)$myrow['price']; |
||
67 | $typeprice = \htmlspecialchars($myrow['typeprice'], ENT_QUOTES | ENT_HTML5); |
||
68 | $town = \htmlspecialchars($myrow['town'], ENT_QUOTES | ENT_HTML5); |
||
69 | $country = \htmlspecialchars($myrow['country'], ENT_QUOTES | ENT_HTML5); |
||
70 | $usid = \htmlspecialchars($myrow['usid'], ENT_QUOTES | ENT_HTML5); |
||
71 | $hits = \htmlspecialchars($myrow['hits'], ENT_QUOTES | ENT_HTML5); |
||
0 ignored issues
–
show
|
|||
72 | |||
73 | if (!XOOPS_USE_MULTIBYTES) { |
||
74 | if (mb_strlen($myrow['title']) >= $options[2]) { |
||
75 | $title = \htmlspecialchars(mb_substr($myrow['title'], 0, $options[2] - 1), ENT_QUOTES | ENT_HTML5) . '...'; |
||
76 | } |
||
77 | } |
||
78 | |||
79 | $sql = 'SELECT nom_type FROM ' . $xoopsDB->prefix('adslight_type') . ' WHERE id_type=' . (int)$type; |
||
80 | $result7 = $xoopsDB->query($sql); |
||
81 | if (!$xoopsDB->isResultSet($result7)) { |
||
82 | \trigger_error("Query Failed! SQL: $sql- Error: " . $xoopsDB->error(), E_USER_ERROR); |
||
83 | } |
||
84 | [$nom_type] = $xoopsDB->fetchRow($result7); |
||
0 ignored issues
–
show
Comprehensibility
Best Practice
introduced
by
|
|||
85 | |||
86 | $sql = 'SELECT nom_price FROM ' . $xoopsDB->prefix('adslight_price') . ' WHERE id_price=' . (int)$typeprice; |
||
87 | $result8 = $xoopsDB->query($sql); |
||
88 | if (!$xoopsDB->isResultSet($result8)) { |
||
89 | \trigger_error("Query Failed! SQL: $sql- Error: " . $xoopsDB->error(), E_USER_ERROR); |
||
90 | } |
||
91 | [$nom_price] = $xoopsDB->fetchRow($result8); |
||
92 | |||
93 | $ad_title = $myrow['title']; |
||
94 | $a_item['status'] = $status; |
||
95 | $a_item['type'] = Utility::getNameType($type); |
||
96 | // $a_item['price'] = $price; |
||
97 | $a_item['typeprice'] = $nom_price; |
||
98 | $a_item['town'] = $town; |
||
99 | $a_item['country'] = $country; |
||
100 | $a_item['id'] = (int)$myrow['lid']; |
||
101 | $a_item['cid'] = (int)$myrow['cid']; |
||
102 | $a_item['no_photo'] = '<a href="' . XOOPS_URL . "/modules/{$moduleDirName}/viewads.php?lid={$a_item['id']}\"><img class=\"thumb\" src=\"" . XOOPS_URL . "/modules/{$moduleDirName}/assets/images/nophoto.jpg\" align=\"left\" width=\"100px\" alt=\"{$ad_title}\"></a>"; |
||
103 | $a_item['price_symbol'] = $helper->getConfig($moduleDirName . '_currency_symbol', ''); |
||
104 | |||
105 | $currencyCode = $helper->getConfig('adslight_currency_code'); |
||
106 | $currencySymbol = $helper->getConfig('adslight_currency_symbol'); |
||
107 | $currencyPosition = $helper->getConfig('currency_position'); |
||
108 | $formattedCurrencyUtilityTemp = Utility::formatCurrencyTemp($price, $currencyCode, $currencySymbol, $currencyPosition); |
||
109 | |||
110 | $priceHtml = $formattedCurrencyUtilityTemp . ' - ' . $nom_price; |
||
111 | |||
112 | $a_item['price'] = $priceHtml; |
||
113 | |||
114 | if (2 === $status) { |
||
115 | $a_item['sold'] = '<img src="assets/images/sold.gif" align="left" alt="">'; |
||
116 | } |
||
117 | |||
118 | if ('' !== $myrow['photo']) { |
||
119 | // $updir = $helper->getConfig($moduleDirName . '_link_upload', ''); |
||
120 | $sql = 'SELECT cod_img, lid, uid_owner, url FROM ' . $xoopsDB->prefix("{$moduleDirName}_pictures") . ' WHERE uid_owner=' . (int)$usid . " AND lid={$a_item['id']} ORDER BY date_created ASC LIMIT 1"; |
||
121 | |||
122 | // if ('' != $myrow['photo']) { |
||
123 | // // $updir = $helper->getConfig($moduleDirName . '_link_upload', ''); |
||
124 | // $sql = 'SELECT cod_img, lid, uid_owner, url FROM ' |
||
125 | // . $xoopsDB->prefix('' . $moduleDirName . '_pictures') |
||
126 | // . ' WHERE uid_owner=' . $xoopsDB->escape($usid) |
||
127 | // . ' AND lid=' . $xoopsDB->escape($myrow['lid']) |
||
128 | // . ' ORDER BY date_created ASC limit 1'; |
||
129 | // } |
||
130 | $resultp = $xoopsDB->query($sql); |
||
131 | if (!$xoopsDB->isResultSet($resultp)) { |
||
132 | \trigger_error("Query Failed! SQL: $sql- Error: " . $xoopsDB->error(), E_USER_ERROR); |
||
133 | } |
||
134 | while ([$cod_img, $pic_lid, $uid_owner, $url] = $xoopsDB->fetchRow($resultp)) { |
||
135 | $a_item['photo'] = '<a href="' . XOOPS_URL . "/modules/{$moduleDirName}/viewads.php?lid={$a_item['id']}\"><img class=\"thumb\" src=\"" . XOOPS_URL . "/uploads/adslight/thumbs/thumb_{$url}\" align=\"left\" width=\"100px\" alt=\"{$title}\"></a>"; |
||
136 | } |
||
137 | } else { |
||
138 | $a_item['photo'] = ''; |
||
139 | } |
||
140 | $a_item['link'] = '<a href="' . XOOPS_URL . "/modules/{$moduleDirName}/viewads.php?lid={$a_item['id']}\"><b>{$title}</b></a>"; |
||
141 | $a_item['date_created'] = formatTimestamp($myrow['date_created'], 's'); |
||
142 | $a_item['hits'] = $myrow['hits']; |
||
143 | |||
144 | $block['items'][] = $a_item; |
||
145 | } |
||
146 | $block['lang_title'] = constant("{$block_lang}_ITEM"); |
||
147 | $block['lang_price'] = constant("{$block_lang}_PRICE"); |
||
148 | $block['lang_typeprice'] = constant("{$block_lang}_TYPEPRICE"); |
||
149 | $block['lang_date'] = constant("{$block_lang}_DATE"); |
||
150 | $block['lang_local'] = constant("{$block_lang}_LOCAL2"); |
||
151 | $block['lang_hits'] = constant("{$block_lang}_HITS"); |
||
152 | $block['link'] = '<a href="' . XOOPS_URL . "/modules/{$moduleDirName}/\"><b>" . constant($block_lang . '_ALL_LISTINGS') . '</b></a><br>'; |
||
153 | $block['add'] = '<a href="' . XOOPS_URL . "/modules/{$moduleDirName}/\"><b>" . constant($block_lang . '_ADDNOW') . '</b></a><br>'; |
||
154 | |||
155 | return $block; |
||
156 | } |
||
157 | |||
158 | /** |
||
159 | * @param $options |
||
160 | * @return string |
||
161 | */ |
||
162 | function adslight_b2_edit($options): string |
||
163 | { |
||
164 | global $xoopsDB; |
||
165 | $moduleDirName = \basename(\dirname(__DIR__)); |
||
166 | $block_lang = '_MB_' . mb_strtoupper($moduleDirName); |
||
167 | |||
168 | $form = constant("{$block_lang}_ORDER") . " <select name='options[]'>"; |
||
169 | $form .= "<option value='date_created'"; |
||
170 | if ('date_created' === $options[0]) { |
||
171 | $form .= " selected='selected'"; |
||
172 | } |
||
173 | $form .= '>' . constant($block_lang . '_DATE') . "</option>\n"; |
||
174 | $form .= "<option value='hits'"; |
||
175 | if ('hits' === $options[0]) { |
||
176 | $form .= " selected='selected'"; |
||
177 | } |
||
178 | $form .= '>' . constant("{$block_lang}_HITS") . '</option>'; |
||
179 | $form .= "</select>\n"; |
||
180 | $form .= ' ' . constant("{$block_lang}_DISP") . " <input type='text' name='options[]' value='{$options[1]}'> " . constant("{$block_lang}_LISTINGS"); |
||
181 | $form .= ' <br><br>' . constant("{$block_lang}_CHARS") . " <input type='text' name='options[]' value='{$options[2]}'> " . constant("{$block_lang}_LENGTH") . '<br><br>'; |
||
182 | |||
183 | return $form; |
||
184 | } |
||
185 |