@@ -165,7 +165,7 @@ public static function edit_blog ($blog_id, $title, $subtitle) {
165165 $ this_blog_id = Database::insert_id ();
166166
167167 //update item_property (update)
168- api_item_property_update (api_get_course_info (), TOOL_BLOGS , Database:: escape_string ($ blog_id ), 'BlogUpdated ' , api_get_user_id ());
168+ api_item_property_update (api_get_course_info (), TOOL_BLOGS , intval ($ blog_id ), 'BlogUpdated ' , api_get_user_id ());
169169
170170 // Update course homepage link
171171 $ sql = "UPDATE $ tbl_tool SET name = ' " .Database::escape_string ($ title )."' WHERE c_id = $ course_id AND link = 'blog/blog.php?blog_id= " .Database::escape_string ((int )$ blog_id )."' LIMIT 1 " ;
@@ -217,7 +217,7 @@ public static function delete_blog ($blog_id) {
217217 Database::query ($ sql );
218218
219219 //update item_property (delete)
220- api_item_property_update (api_get_course_info (), TOOL_BLOGS , Database:: escape_string ($ blog_id ), 'delete ' , api_get_user_id ());
220+ api_item_property_update (api_get_course_info (), TOOL_BLOGS , intval ($ blog_id ), 'delete ' , api_get_user_id ());
221221 }
222222
223223 /**
@@ -278,7 +278,7 @@ public static function create_post ($title, $full_text, $file_comment, $blog_id)
278278 // Storing the attachments if any
279279 if ($ result ) {
280280 $ sql ='INSERT INTO ' .$ blog_table_attachment .'(c_id, filename,comment, path, post_id,size, blog_id,comment_id) ' .
281- "VALUES ( $ course_id, ' " .Database::escape_string ($ file_name )."', ' " .Database:: escape_string ( $ comment) ."', ' " .Database::escape_string ($ new_file_name )."' , ' " .$ last_post_id ."', ' " .intval ($ _FILES ['user_upload ' ]['size ' ])."', ' " .$ blog_id ."', '0' ) " ;
281+ "VALUES ( $ course_id, ' " .Database::escape_string ($ file_name )."', ' " .$ comment ."', ' " .Database::escape_string ($ new_file_name )."' , ' " .$ last_post_id ."', ' " .intval ($ _FILES ['user_upload ' ]['size ' ])."', ' " .$ blog_id ."', '0' ) " ;
282282 $ result =Database::query ($ sql );
283283 $ message .=' / ' .get_lang ('AttachmentUpload ' );
284284 }
@@ -404,7 +404,7 @@ public static function create_comment($title, $full_text, $file_comment,$blog_id
404404 if ($ result )
405405 {
406406 $ sql ='INSERT INTO ' .$ blog_table_attachment .'(c_id, filename,comment, path, post_id,size,blog_id,comment_id) ' .
407- "VALUES ( $ course_id, ' " .Database::escape_string ($ file_name )."', ' " .Database:: escape_string ( $ comment) ."', ' " .Database::escape_string ($ new_file_name )."' , ' " .$ post_id ."', ' " .$ _FILES ['user_upload ' ]['size ' ]."', ' " .$ blog_id ."', ' " .$ last_id ."' ) " ;
407+ "VALUES ( $ course_id, ' " .Database::escape_string ($ file_name )."', ' " .$ comment ."', ' " .Database::escape_string ($ new_file_name )."' , ' " .$ post_id ."', ' " .$ _FILES ['user_upload ' ]['size ' ]."', ' " .$ blog_id ."', ' " .$ last_id ."' ) " ;
408408 $ result =Database::query ($ sql );
409409 $ message .=' / ' .get_lang ('AttachmentUpload ' );
410410 }
@@ -423,9 +423,9 @@ public static function delete_comment ($blog_id, $post_id, $comment_id) {
423423 // Init
424424 $ tbl_blogs_comments = Database::get_course_table (TABLE_BLOGS_COMMENTS );
425425 $ tbl_blogs_rating = Database::get_course_table (TABLE_BLOGS_RATING );
426- $ blog_id = Database:: escape_string ($ blog_id );
427- $ post_id = Database:: escape_string ($ post_id );
428- $ comment_id = Database:: escape_string ($ comment_id );
426+ $ blog_id = intval ($ blog_id );
427+ $ post_id = intval ($ post_id );
428+ $ comment_id = intval ($ comment_id );
429429
430430 $ course_id = api_get_course_int_id ();
431431
@@ -2713,9 +2713,9 @@ function get_blog_attachment($blog_id, $post_id=null,$comment_id=null)
27132713{
27142714 $ blog_table_attachment = Database::get_course_table (TABLE_BLOGS_ATTACHMENT );
27152715
2716- $ blog_id = Database:: escape_string ($ blog_id );
2717- $ comment_id = Database:: escape_string ($ comment_id );
2718- $ post_id = Database:: escape_string ($ post_id );
2716+ $ blog_id = intval ($ blog_id );
2717+ $ comment_id = intval ($ comment_id );
2718+ $ post_id = intval ($ post_id );
27192719 $ row =array ();
27202720 $ where ='' ;
27212721 if (!empty ($ post_id ) && is_numeric ($ post_id )) {
@@ -2754,9 +2754,9 @@ function delete_all_blog_attachment($blog_id,$post_id=null,$comment_id=null)
27542754
27552755 global $ _course ;
27562756 $ blog_table_attachment = Database::get_course_table (TABLE_BLOGS_ATTACHMENT );
2757- $ blog_id = Database:: escape_string ($ blog_id );
2758- $ comment_id = Database:: escape_string ($ comment_id );
2759- $ post_id = Database:: escape_string ($ post_id );
2757+ $ blog_id = intval ($ blog_id );
2758+ $ comment_id = intval ($ comment_id );
2759+ $ post_id = intval ($ post_id );
27602760
27612761 $ course_id = api_get_course_int_id ();
27622762
@@ -2836,7 +2836,7 @@ function get_blog_post_from_user($course_code, $user_id) {
28362836function get_blog_comment_from_user ($ course_code , $ user_id ) {
28372837 $ tbl_blogs = Database::get_course_table (TABLE_BLOGS );
28382838 $ tbl_blog_comment = Database::get_course_table (TABLE_BLOGS_COMMENTS );
2839- $ user_id = Database:: escape_string ($ user_id );
2839+ $ user_id = intval ($ user_id );
28402840
28412841 $ course_info = api_get_course_info ($ course_code );
28422842 $ course_id = $ course_info ['real_id ' ];
0 commit comments