diff options
| -rw-r--r-- | series/trunk/includes/instadisc.php | 4 |
1 files changed, 2 insertions, 2 deletions
| diff --git a/series/trunk/includes/instadisc.php b/series/trunk/includes/instadisc.php index 189cf96..b7b5ed0 100644 --- a/series/trunk/includes/instadisc.php +++ b/series/trunk/includes/instadisc.php | |||
| @@ -77,7 +77,7 @@ function instaDisc_initSubscription($username, $subscriptionID, $subscriptionURL | |||
| 77 | $getsub = "SELECT * FROM subscriptions WHERE identity = \"" . mysql_real_escape_string($seriesID) . "\""; | 77 | $getsub = "SELECT * FROM subscriptions WHERE identity = \"" . mysql_real_escape_string($seriesID) . "\""; |
| 78 | $getsub2 = mysql_query($getsub); | 78 | $getsub2 = mysql_query($getsub); |
| 79 | $getsub3 = mysql_fetch_array($getsub2); | 79 | $getsub3 = mysql_fetch_array($getsub2); |
| 80 | if ($getsub3['identity'] == $seriesID) | 80 | if ($getsub3['identity'] == $subscriptionID) |
| 81 | { | 81 | { |
| 82 | if (!instaDisc_isAdmin($username) && ($getsub3['username'] != $username)) | 82 | if (!instaDisc_isAdmin($username) && ($getsub3['username'] != $username)) |
| 83 | { | 83 | { |
| @@ -87,7 +87,7 @@ function instaDisc_initSubscription($username, $subscriptionID, $subscriptionURL | |||
| 87 | $setsub = "UPDATE subscriptions SET title = \"" . mysql_real_escape_string($subscriptionTitle) . "\", url = \"" . mysql_real_escape_string($subscriptionURL) . "\", category = \"" . mysql_real_escape_string($subscriptionCategory) . "\", personal = \"" . mysql_real_escape_string($subscriptionPersonal) . "\", password = \"" . mysql_real_escape_string($subscriptionPassword) . "\" WHERE identity = \"" . mysql_real_escape_string($subscriptionID) . "\""; | 87 | $setsub = "UPDATE subscriptions SET title = \"" . mysql_real_escape_string($subscriptionTitle) . "\", url = \"" . mysql_real_escape_string($subscriptionURL) . "\", category = \"" . mysql_real_escape_string($subscriptionCategory) . "\", personal = \"" . mysql_real_escape_string($subscriptionPersonal) . "\", password = \"" . mysql_real_escape_string($subscriptionPassword) . "\" WHERE identity = \"" . mysql_real_escape_string($subscriptionID) . "\""; |
| 88 | $setsub2 = mysql_query($setsub); | 88 | $setsub2 = mysql_query($setsub); |
| 89 | } else { | 89 | } else { |
| 90 | $inssub = "INSERT INTO subscriptions (identity, title, url, category, personal, username, password) VALUES (\"" . mysql_real_escape_string($seriesID) . "\",\"" . mysql_real_escape_string($subscriptionTitle) . "\",\"" . mysql_real_escape_string($subscriptionURL) . "\",\"" . mysql_real_escape_string($subscriptionCategory) . "\",\"" . mysql_real_escape_string($subscriptionPersonal) . "\",\"" . mysql_real_escape_string($username) . "\",\"" . mysql_real_escape_string($subscriptionPassword) . "\")"; | 90 | $inssub = "INSERT INTO subscriptions (identity, title, url, category, personal, username, password) VALUES (\"" . mysql_real_escape_string($subscriptionID) . "\",\"" . mysql_real_escape_string($subscriptionTitle) . "\",\"" . mysql_real_escape_string($subscriptionURL) . "\",\"" . mysql_real_escape_string($subscriptionCategory) . "\",\"" . mysql_real_escape_string($subscriptionPersonal) . "\",\"" . mysql_real_escape_string($username) . "\",\"" . mysql_real_escape_string($subscriptionPassword) . "\")"; |
| 91 | $inssub2 = mysql_query($inssub); | 91 | $inssub2 = mysql_query($inssub); |
| 92 | } | 92 | } |
| 93 | 93 | ||
