Changeset 23554 for trunk/wp-includes/ms-functions.php
- Timestamp:
- 03/01/2013 04:28:40 PM (12 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/wp-includes/ms-functions.php
r23535 r23554 280 280 */ 281 281 function create_empty_blog( $domain, $path, $weblog_title, $site_id = 1 ) { 282 $domain = addslashes( $domain ); 283 $weblog_title = addslashes( $weblog_title ); 284 282 285 if ( empty($path) ) 283 286 $path = '/'; … … 580 583 $blogname = apply_filters( 'newblogname', $blogname ); 581 584 582 $blog_title = $blog_title;585 $blog_title = stripslashes( $blog_title ); 583 586 584 587 if ( empty( $blog_title ) ) … … 633 636 634 637 $key = substr( md5( time() . rand() . $domain ), 0, 16 ); 635 $meta = serialize( $meta ); 638 $meta = serialize($meta); 639 $domain = $wpdb->escape($domain); 640 $path = $wpdb->escape($path); 641 $title = $wpdb->escape($title); 636 642 637 643 $wpdb->insert( $wpdb->signups, array( … … 646 652 ) ); 647 653 648 wpmu_signup_blog_notification( $domain, $path, $title, $user, $user_email, $key, $meta);654 wpmu_signup_blog_notification($domain, $path, $title, $user, $user_email, $key, $meta); 649 655 } 650 656 … … 835 841 836 842 $meta = maybe_unserialize($signup->meta); 837 $user_login = $ signup->user_login;838 $user_email = $ signup->user_email;843 $user_login = $wpdb->escape($signup->user_login); 844 $user_email = $wpdb->escape($signup->user_email); 839 845 $password = wp_generate_password( 12, false ); 840 846 … … 1152 1158 update_option( 'upload_path', get_blog_option( $current_site->blog_id, 'upload_path' ) ); 1153 1159 1154 update_option( 'blogname', $blog_title);1160 update_option( 'blogname', stripslashes( $blog_title ) ); 1155 1161 update_option( 'admin_email', '' ); 1156 1162 … … 1209 1215 return false; 1210 1216 1211 $welcome_email = get_site_option( 'welcome_email');1217 $welcome_email = stripslashes( get_site_option( 'welcome_email' ) ); 1212 1218 if ( $welcome_email == false ) 1213 $welcome_email = __( 'Dear User,1219 $welcome_email = stripslashes( __( 'Dear User, 1214 1220 1215 1221 Your new SITE_NAME site has been successfully set up at: … … 1223 1229 We hope you enjoy your new site. Thanks! 1224 1230 1225 --The Team @ SITE_NAME' ) ;1231 --The Team @ SITE_NAME' ) ); 1226 1232 1227 1233 $url = get_blogaddress_by_id($blog_id); … … 1247 1253 $current_site->site_name = 'WordPress'; 1248 1254 1249 $subject = apply_filters( 'update_welcome_subject', sprintf(__('New %1$s Site: %2$s'), $current_site->site_name, $title) );1255 $subject = apply_filters( 'update_welcome_subject', sprintf(__('New %1$s Site: %2$s'), $current_site->site_name, stripslashes( $title ) ) ); 1250 1256 wp_mail($user->user_email, $subject, $message, $message_headers); 1251 1257 return true; … … 1476 1482 global $wpdb; 1477 1483 $user = get_userdata( (int) $user_id ); 1478 $wpdb->insert( $wpdb->registration_log, array('email' => $user->user_email, 'IP' => preg_replace( '/[^0-9., ]/', '', wp_unslash( $_SERVER['REMOTE_ADDR'] )), 'blog_id' => $blog_id, 'date_registered' => current_time('mysql')) );1484 $wpdb->insert( $wpdb->registration_log, array('email' => $user->user_email, 'IP' => preg_replace( '/[^0-9., ]/', '',$_SERVER['REMOTE_ADDR'] ), 'blog_id' => $blog_id, 'date_registered' => current_time('mysql')) ); 1479 1485 } 1480 1486
Note: See TracChangeset
for help on using the changeset viewer.