[TEP-COMMIT] [CVS catalog] replace calls to the database functions with the new database class

hpdl-OfajU3CKLf1/[email protected] 7 Mar 2005 10:04:46 -0000
Newsgroups gmane.comp.web.oscommerce.cvs
Message-ID <[email protected]>
<html>
<head>
<style><!--
  body {background-color:#ffffff;}
  .file {border:1px solid #eeeeee;margin-top:1em;margin-bottom:1em;}
  .pathname {font-family:monospace; float:right;}
  .fileheader {margin-bottom:.5em;}
  .diff {margin:0;}
  .tasklist {padding:4px;border:1px dashed #000000;margin-top:1em;}
  .tasklist ul {margin-top:0;margin-bottom:0;}
  tr.alt {background-color:#eeeeee}
  #added {background-color:#ddffdd;}
  #addedchars {background-color:#99ff99;font-weight:bolder;}
  tr.alt #added {background-color:#ccf7cc;}
  #removed {background-color:#ffdddd;}
  #removedchars {background-color:#ff9999;font-weight:bolder;}
  tr.alt #removed {background-color:#f7cccc;}
  #info {color:#888888;}
  #context {background-color:#eeeeee;}
  td {padding-left:.3em;padding-right:.3em;}
  tr.head {border-bottom-width:1px;border-bottom-style:solid;}
  tr.head td {padding:0;padding-top:.2em;}
  .task {background-color:#ffff00;}
  .comment {padding:4px;border:1px dashed #000000;background-color:#ffffdd}
  .error {color:red;}
  hr {border-width:0px;height:2px;background:black;}
--></style>
</head>
<body>
<table cellspacing="0" cellpadding="0" border="0" rules="cols">
<tr class="head"><td colspan="4">Commit in <b><tt>catalog/catalog</tt></b><span id="info"> on MAIN</span></td></tr>
<tr><td><tt><a href="#file1">account_newsletters.php</a></tt></td><td align="right" id="added">+2</td><td align="right" id="removed">-2</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php?rev=1.7&amp;content-type=text/vnd.viewcvs-markup">1.7</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php.diff?r1=1.7&amp;r2=1.8">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php?rev=1.8&amp;content-type=text/vnd.viewcvs-markup">1.8</a></td></tr>
<tr class="alt"><td><tt><a href="#file2">account_notifications.php</a></tt></td><td align="right" id="added">+1</td><td align="right" id="removed">-1</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php?rev=1.5&amp;content-type=text/vnd.viewcvs-markup">1.5</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php.diff?r1=1.5&amp;r2=1.6">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php?rev=1.6&amp;content-type=text/vnd.viewcvs-markup">1.6</a></td></tr>
<tr><td><tt><a href="#file3">advanced_search_result.php</a></tt></td><td align="right" id="added">+4</td><td align="right" id="removed">-4</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php?rev=1.75&amp;content-type=text/vnd.viewcvs-markup">1.75</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php.diff?r1=1.75&amp;r2=1.76">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php?rev=1.76&amp;content-type=text/vnd.viewcvs-markup">1.76</a></td></tr>
<tr class="alt"><td><tt><a href="#file4">checkout_confirmation.php</a></tt></td><td align="right" id="added">+2</td><td align="right" id="removed">-2</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php?rev=1.145&amp;content-type=text/vnd.viewcvs-markup">1.145</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php.diff?r1=1.145&amp;r2=1.146">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php?rev=1.146&amp;content-type=text/vnd.viewcvs-markup">1.146</a></td></tr>
<tr><td><tt><a href="#file5">checkout_shipping.php</a></tt></td><td align="right" id="added">+1</td><td align="right" id="removed">-1</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.24&amp;content-type=text/vnd.viewcvs-markup">1.24</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php.diff?r1=1.24&amp;r2=1.25">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.25&amp;content-type=text/vnd.viewcvs-markup">1.25</a></td></tr>
<tr class="alt"><td><tt><a href="#file6">contact_us.php</a></tt></td><td align="right" id="added">+4</td><td align="right" id="removed">-4</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php?rev=1.45&amp;content-type=text/vnd.viewcvs-markup">1.45</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php.diff?r1=1.45&amp;r2=1.46">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php?rev=1.46&amp;content-type=text/vnd.viewcvs-markup">1.46</a></td></tr>
<tr><td><tt><a href="#file7">index.php</a></tt></td><td align="right" id="added">+64</td><td align="right" id="removed">-31</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php?rev=1.8&amp;content-type=text/vnd.viewcvs-markup">1.8</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php.diff?r1=1.8&amp;r2=1.9">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php?rev=1.9&amp;content-type=text/vnd.viewcvs-markup">1.9</a></td></tr>
<tr class="alt"><td><tt><a href="#file8">login.php</a></tt></td><td align="right" id="added">+13</td><td align="right" id="removed">-10</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php?rev=1.84&amp;content-type=text/vnd.viewcvs-markup">1.84</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php.diff?r1=1.84&amp;r2=1.85">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php?rev=1.85&amp;content-type=text/vnd.viewcvs-markup">1.85</a></td></tr>
<tr><td><tt><a href="#file9">password_forgotten.php</a></tt></td><td align="right" id="added">+12</td><td align="right" id="removed">-9</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php.diff?r1=1.53&amp;r2=1.54">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php?rev=1.54&amp;content-type=text/vnd.viewcvs-markup">1.54</a></td></tr>
<tr class="alt"><td><tt><a href="#file10">popup_image.php</a></tt></td><td align="right" id="added">+9</td><td align="right" id="removed">-5</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php?rev=1.19&amp;content-type=text/vnd.viewcvs-markup">1.19</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php.diff?r1=1.19&amp;r2=1.20">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php?rev=1.20&amp;content-type=text/vnd.viewcvs-markup">1.20</a></td></tr>
<tr><td><tt><a href="#file11">product_info.php</a></tt></td><td align="right" id="added">+80</td><td align="right" id="removed">-44</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php?rev=1.106&amp;content-type=text/vnd.viewcvs-markup">1.106</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php.diff?r1=1.106&amp;r2=1.107">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php?rev=1.107&amp;content-type=text/vnd.viewcvs-markup">1.107</a></td></tr>
<tr class="alt"><td><tt><a href="#file12">product_reviews.php</a></tt></td><td align="right" id="added">+40</td><td align="right" id="removed">-29</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php?rev=1.55&amp;content-type=text/vnd.viewcvs-markup">1.55</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php.diff?r1=1.55&amp;r2=1.56">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php?rev=1.56&amp;content-type=text/vnd.viewcvs-markup">1.56</a></td></tr>
<tr><td><tt><a href="#file13">product_reviews_info.php</a></tt></td><td align="right" id="added">+34</td><td align="right" id="removed">-21</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php?rev=1.56&amp;content-type=text/vnd.viewcvs-markup">1.56</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php.diff?r1=1.56&amp;r2=1.57">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php?rev=1.57&amp;content-type=text/vnd.viewcvs-markup">1.57</a></td></tr>
<tr class="alt"><td><tt><a href="#file14">product_reviews_write.php</a></tt></td><td align="right" id="added">+41</td><td align="right" id="removed">-47</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php?rev=1.61&amp;content-type=text/vnd.viewcvs-markup">1.61</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php.diff?r1=1.61&amp;r2=1.62">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php?rev=1.62&amp;content-type=text/vnd.viewcvs-markup">1.62</a></td></tr>
<tr><td><tt><a href="#file15">products_new.php</a></tt></td><td align="right" id="added">+26</td><td align="right" id="removed">-20</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php?rev=1.31&amp;content-type=text/vnd.viewcvs-markup">1.31</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php.diff?r1=1.31&amp;r2=1.32">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php?rev=1.32&amp;content-type=text/vnd.viewcvs-markup">1.32</a></td></tr>
<tr class="alt"><td><tt><a href="#file16">redirect.php</a></tt></td><td align="right" id="added">+28</td><td align="right" id="removed">-18</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php?rev=1.13&amp;content-type=text/vnd.viewcvs-markup">1.13</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php.diff?r1=1.13&amp;r2=1.14">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php?rev=1.14&amp;content-type=text/vnd.viewcvs-markup">1.14</a></td></tr>
<tr><td><tt><a href="#file17">reviews.php</a></tt></td><td align="right" id="added">+33</td><td align="right" id="removed">-26</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php.diff?r1=1.53&amp;r2=1.54">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php?rev=1.54&amp;content-type=text/vnd.viewcvs-markup">1.54</a></td></tr>
<tr class="alt"><td><tt><a href="#file18">shopping_cart.php</a></tt></td><td align="right" id="added">+16</td><td align="right" id="removed">-15</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php?rev=1.76&amp;content-type=text/vnd.viewcvs-markup">1.76</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php.diff?r1=1.76&amp;r2=1.77">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php?rev=1.77&amp;content-type=text/vnd.viewcvs-markup">1.77</a></td></tr>
<tr><td><tt><a href="#file19">specials.php</a></tt></td><td align="right" id="added">+22</td><td align="right" id="removed">-13</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php?rev=1.52&amp;content-type=text/vnd.viewcvs-markup">1.52</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php.diff?r1=1.52&amp;r2=1.53">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a></td></tr>
<tr class="alt"><td><tt><a href="#file20">tell_a_friend.php</a></tt></td><td align="right" id="added">+23</td><td align="right" id="removed">-21</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php?rev=1.44&amp;content-type=text/vnd.viewcvs-markup">1.44</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php.diff?r1=1.44&amp;r2=1.45">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php?rev=1.45&amp;content-type=text/vnd.viewcvs-markup">1.45</a></td></tr>
<tr><td><tt>includes/<a href="#file21">application_top.php</a></tt></td><td></td><td align="right" id="removed">-6</td><td nowrap="nowrap" align="center"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php?rev=1.289&amp;content-type=text/vnd.viewcvs-markup">1.289</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php.diff?r1=1.289&amp;r2=1.290">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php?rev=1.290&amp;content-type=text/vnd.viewcvs-markup">1.290</a></td></tr>
<tr class="alt"><td><tt>includes/classes/<span id="removed">split_page_results.php</span></tt></td><td></td><td></td><td nowrap="nowrap"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/classes/split_page_results.php?rev=1.17&amp;content-type=text/vnd.viewcvs-markup">1.17</a> removed</td></tr>
<tr><td><tt>includes/functions/<span id="removed">database.php</span></tt></td><td></td><td></td><td nowrap="nowrap"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/functions/database.php?rev=1.23&amp;content-type=text/vnd.viewcvs-markup">1.23</a> removed</td></tr>
<tr><td></td><td align="right" id="added">+455</td><td align="right" id="removed">-329</td><td></td></tr>
</table>
<small id="info">2 removed + 21 modified, total 23 files</small><br />
<pre class="comment">
replace calls to the database functions with the new database class

remove redundant database functions file and split page results class
</pre>
<hr /><a name="file1" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>account_newsletters.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php?rev=1.7&amp;content-type=text/vnd.viewcvs-markup">1.7</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php.diff?r1=1.7&amp;r2=1.8">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_newsletters.php?rev=1.8&amp;content-type=text/vnd.viewcvs-markup">1.8</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.7 -r1.8
--- account_newsletters.php	2005/02/23 15:25:10	1.7
+++ account_newsletters.php	2005/03/07 10:04:34	1.8
@@ -28,12 +28,12 @@
</small></pre><pre class="diff" id="context"> 
   if (isset($_POST['action']) &amp;&amp; ($_POST['action'] == 'process')) {
     if (isset($_POST['newsletter_general']) &amp;&amp; is_numeric($_POST['newsletter_general'])) {
</pre><pre class="diff" id="removed">-      $newsletter_general = tep_db_prepare_input($_POST['newsletter_general']);
</pre><pre class="diff" id="added">+      $newsletter_general = $_POST['newsletter_general'];
</pre><pre class="diff" id="context">     } else {
       $newsletter_general = '0';
     }
 
</pre><pre class="diff" id="removed">-    if ($newsletter_general != $Qnewsletter-&gt;value('customers_newsletter')) {
</pre><pre class="diff" id="added">+    if ($newsletter_general != $Qnewsletter-&gt;value<span id="addedchars">Int</span>('customers_newsletter')) {
</pre><pre class="diff" id="context">       $newsletter_general = (($Qnewsletter-&gt;value('customers_newsletter') == '1') ? '0' : '1');
 
       $Qupdate = $osC_Database-&gt;query('update :table_customers set customers_newsletter = :customers_newsletter where customers_id = :customers_id');
</pre></div>
<hr /><a name="file2" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>account_notifications.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php?rev=1.5&amp;content-type=text/vnd.viewcvs-markup">1.5</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php.diff?r1=1.5&amp;r2=1.6">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/account_notifications.php?rev=1.6&amp;content-type=text/vnd.viewcvs-markup">1.6</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.5 -r1.6
--- account_notifications.php	2005/02/23 15:24:25	1.5
+++ account_notifications.php	2005/03/07 10:04:35	1.6
@@ -30,7 +30,7 @@
</small></pre><pre class="diff" id="context">     $updated = false;
 
     if (isset($_POST['product_global']) &amp;&amp; is_numeric($_POST['product_global'])) {
</pre><pre class="diff" id="removed">-      $product_global = tep_db_prepare_input($_POST['product_global']);
</pre><pre class="diff" id="added">+      $product_global = $_POST['product_global'];
</pre><pre class="diff" id="context">     } else {
       $product_global = '0';
     }
</pre></div>
<hr /><a name="file3" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>advanced_search_result.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php?rev=1.75&amp;content-type=text/vnd.viewcvs-markup">1.75</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php.diff?r1=1.75&amp;r2=1.76">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/advanced_search_result.php?rev=1.76&amp;content-type=text/vnd.viewcvs-markup">1.76</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.75 -r1.76
--- advanced_search_result.php	2004/04/16 14:05:34	1.75
+++ advanced_search_result.php	2005/03/07 10:04:35	1.76
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -238,9 +238,9 @@
</small></pre><pre class="diff" id="context">           $where_str .= " " . $search_keywords[$i] . " ";
           break;
         default:
</pre><pre class="diff" id="removed">-          $keyword = tep_db_prepare_input($search_keywords[$i]);
-          $where_str .= "(pd.products_name like '%" . tep_db_input($keyword) . "%' or p.products_model like '%" . tep_db_input($keyword) . "%' or m.manufacturers_name like '%" . tep_db_input($keyword) . "%'";
-          if (isset($_GET['search_in_description']) &amp;&amp; ($_GET['search_in_description'] == '1')) $where_str .= " or pd.products_description like '%" . tep_db_input($keyword) . "%'";
</pre><pre class="diff" id="added">+          $keyword = tep_sanitize_string($search_keywords[$i]);
+          $where_str .= "(pd.products_name like '%" . addslashes($keyword) . "%' or p.products_model like '%" . addslashes($keyword) . "%' or m.manufacturers_name like '%" . addslashes($keyword) . "%'";
+          if (isset($_GET['search_in_description']) &amp;&amp; ($_GET['search_in_description'] == '1')) $where_str .= " or pd.products_description like '%" . addslashes($keyword) . "%'";
</pre><pre class="diff" id="context">           $where_str .= ')';
           break;
       }
</pre></div>
<hr /><a name="file4" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_confirmation.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php?rev=1.145&amp;content-type=text/vnd.viewcvs-markup">1.145</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php.diff?r1=1.145&amp;r2=1.146">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_confirmation.php?rev=1.146&amp;content-type=text/vnd.viewcvs-markup">1.146</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.145 -r1.146
--- checkout_confirmation.php	2004/07/22 17:23:53	1.145
+++ checkout_confirmation.php	2005/03/07 10:04:35	1.146
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -44,7 +44,7 @@
</small></pre><pre class="diff" id="context">   if ( (isset($_POST['comments'])) &amp;&amp; ($osC_Session-&gt;exists('comments')) &amp;&amp; (empty($_POST['comments'])) ) {
     $osC_Session-&gt;remove('comments');
   } else if (tep_not_null($_POST['comments'])) {
</pre><pre class="diff" id="removed">-    $osC_Session-&gt;set('comments', tep_<span id="removedchars">db_prepare_input</span>($_POST['comments']));
</pre><pre class="diff" id="added">+    $osC_Session-&gt;set('comments', tep_<span id="addedchars">sanitize_string</span>($_POST['comments']));
</pre><pre class="diff" id="context">   }
 
   if (DISPLAY_CONDITIONS_ON_CHECKOUT == 'true') {
</pre></div>
<hr /><a name="file5" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>checkout_shipping.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.24&amp;content-type=text/vnd.viewcvs-markup">1.24</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php.diff?r1=1.24&amp;r2=1.25">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/checkout_shipping.php?rev=1.25&amp;content-type=text/vnd.viewcvs-markup">1.25</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.24 -r1.25
--- checkout_shipping.php	2005/02/23 15:28:27	1.24
+++ checkout_shipping.php	2005/03/07 10:04:35	1.25
@@ -106,7 +106,7 @@
</small></pre><pre class="diff" id="context"> // process the selected shipping method
   if (isset($_POST['action']) &amp;&amp; ($_POST['action'] == 'process')) {
     if (tep_not_null($_POST['comments'])) {
</pre><pre class="diff" id="removed">-      $osC_Session-&gt;set('comments', tep_<span id="removedchars">db_prepare_input</span>($_POST['comments']));
</pre><pre class="diff" id="added">+      $osC_Session-&gt;set('comments', tep_<span id="addedchars">sanitize_string</span>($_POST['comments']));
</pre><pre class="diff" id="context">     }
 
     if ( (tep_count_shipping_modules() &gt; 0) || ($free_shipping == true) ) {
</pre></div>
<hr /><a name="file6" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>contact_us.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php?rev=1.45&amp;content-type=text/vnd.viewcvs-markup">1.45</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php.diff?r1=1.45&amp;r2=1.46">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/contact_us.php?rev=1.46&amp;content-type=text/vnd.viewcvs-markup">1.46</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.45 -r1.46
--- contact_us.php	2004/07/22 17:23:53	1.45
+++ contact_us.php	2005/03/07 10:04:35	1.46
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -16,9 +16,9 @@
</small></pre><pre class="diff" id="context"> 
   $error = false;
   if (isset($_GET['action']) &amp;&amp; ($_GET['action'] == 'send')) {
</pre><pre class="diff" id="removed">-    $name = tep_db_prepare_input($_POST['name']);
-    $email_address = tep_db_prepare_input($_POST['email']);
-    $enquiry = tep_db_prepare_input($_POST['enquiry']);
</pre><pre class="diff" id="added">+    $name = tep_sanitize_string($_POST['name']);
+    $email_address = tep_sanitize_string($_POST['email']);
+    $enquiry = tep_sanitize_string($_POST['enquiry']);
</pre><pre class="diff" id="context"> 
     if (tep_validate_email($email_address)) {
       tep_mail(STORE_OWNER, STORE_OWNER_EMAIL_ADDRESS, EMAIL_SUBJECT, $enquiry, $name, $email_address);
</pre></div>
<hr /><a name="file7" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>index.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php?rev=1.8&amp;content-type=text/vnd.viewcvs-markup">1.8</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php.diff?r1=1.8&amp;r2=1.9">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/index.php?rev=1.9&amp;content-type=text/vnd.viewcvs-markup">1.9</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.8 -r1.9
--- index.php	2004/07/22 17:23:53	1.8
+++ index.php	2005/03/07 10:04:35	1.9
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,14 +15,20 @@
</small></pre><pre class="diff" id="context"> // the following cPath references come from application_top.php
   $category_depth = 'top';
   if (isset($cPath) &amp;&amp; tep_not_null($cPath)) {
</pre><pre class="diff" id="removed">-    $categories_products_query = tep_db_query("select count(*) as total from " . TABLE_PRODUCTS_TO_CATEGORIES . " where categories_id = '" . (int)$current_category_id . "'");
-    $cateqories_products = tep_db_fetch_array($categories_products_query);
-    if ($cateqories_products['total'] &gt; 0) {
</pre><pre class="diff" id="added">+    $Qproducts = $osC_Database-&gt;query('select count(*) as total from :table_products_to_categories where categories_id = :categories_id');
+    $Qproducts-&gt;bindTable(':table_products_to_categories', TABLE_PRODUCTS_TO_CATEGORIES);
+    $Qproducts-&gt;bindInt(':categories_id', $current_category_id);
+    $Qproducts-&gt;execute();
+
+    if ($Qproducts-&gt;valueInt('total') &gt; 0) {
</pre><pre class="diff" id="context">       $category_depth = 'products'; // display products
     } else {
</pre><pre class="diff" id="removed">-      $category_parent_query = tep_db_query("select count(*) as total from " . TABLE_CATEGORIES . " where parent_id = '" . (int)$current_category_id . "'");
-      $category_parent = tep_db_fetch_array($category_parent_query);
-      if ($category_parent['total'] &gt; 0) {
</pre><pre class="diff" id="added">+      $Qparent = $osC_Database-&gt;query('select count(*) as total from :table_categories where parent_id = :parent_id');
+      $Qparent-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+      $Qparent-&gt;bindInt(':parent_id', $current_category_id);
+      $Qparent-&gt;execute();
+
+      if ($Qparent-&gt;valueInt('total') &gt; 0) {
</pre><pre class="diff" id="context">         $category_depth = 'nested'; // navigate through the categories
       } else {
         $category_depth = 'products'; // category has no products, but display the 'no products' message
</pre><pre class="diff"><small id="info">@@ -56,15 +62,19 @@
</small></pre><pre class="diff" id="context"> &lt;!-- body_text //--&gt;
 &lt;?php
   if ($category_depth == 'nested') {
</pre><pre class="diff" id="removed">-    $category_query = tep_db_query("select cd.categories_name, c.categories_image from " . TABLE_CATEGORIES . " c, " . TABLE_CATEGORIES_DESCRIPTION . " cd where c.categories_id = '" . (int)$current_category_id . "' and cd.categories_id = '" . (int)$current_category_id . "' and cd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-    $category = tep_db_fetch_array($category_query);
</pre><pre class="diff" id="added">+    $Qcategory = $osC_Database-&gt;query('select cd.categories_name, c.categories_image from :table_categories c, :table_categories_description cd where c.categories_id = :categories_id and c.categories_id = cd.categories_id and cd.language_id = :language_id');
+    $Qcategory-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+    $Qcategory-&gt;bindTable(':table_categories_description', TABLE_CATEGORIES_DESCRIPTION);
+    $Qcategory-&gt;bindInt(':categories_id', $current_category_id);
+    $Qcategory-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+    $Qcategory-&gt;execute();
</pre><pre class="diff" id="context"> ?&gt;
     &lt;td width="100%" valign="top"&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="0"&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="0"&gt;
           &lt;tr&gt;
             &lt;td class="pageHeading"&gt;&lt;?php echo HEADING_TITLE; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="pageHeading" align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . $category['categories_image'], $category['categories_name'], HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="pageHeading" align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . $Qcategory-&gt;value('categories_image'), $Qcategory-&gt;value('categories_name'), HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -81,27 +91,42 @@
</small></pre><pre class="diff" id="context"> // check to see if there are deeper categories within the current category
       $category_links = array_reverse($cPath_array);
       for($i=0, $n=sizeof($category_links); $i&lt;$n; $i++) {
</pre><pre class="diff" id="removed">-        $categories_query = tep_db_query("select count(*) as total from " . TABLE_CATEGORIES . " c, " . TABLE_CATEGORIES_DESCRIPTION . " cd where c.parent_id = '" . (int)$category_links[$i] . "' and c.categories_id = cd.categories_id and cd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-        $categories = tep_db_fetch_array($categories_query);
-        if ($categories['total'] &lt; 1) {
</pre><pre class="diff" id="added">+        $Qcategories = $osC_Database-&gt;query('select count(*) as total from :table_categories c, :table_categories_description cd where c.parent_id = :parent_id and c.categories_id = cd.categories_id and cd.language_id = :language_id');
+        $Qcategories-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+        $Qcategories-&gt;bindTable(':table_categories_description', TABLE_CATEGORIES_DESCRIPTION);
+        $Qcategories-&gt;bindInt(':parent_id', $category_links[$i]);
+        $Qcategories-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+        $Qcategories-&gt;execute();
+
+        if ($Qcategories-&gt;valueInt('total') &lt; 1) {
</pre><pre class="diff" id="context">           // do nothing, go through the loop
         } else {
</pre><pre class="diff" id="removed">-          $categories_query = tep_db_query("select c.categories_id, cd.categories_name, c.categories_image, c.parent_id from " . TABLE_CATEGORIES . " c, " . TABLE_CATEGORIES_DESCRIPTION . " cd where c.parent_id = '" . (int)$category_links[$i] . "' and c.categories_id = cd.categories_id and cd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' order by sort_order, cd.categories_name");
</pre><pre class="diff" id="added">+          $Qcategories = $osC_Database-&gt;query('select c.categories_id, cd.categories_name, c.categories_image, c.parent_id from :table_categories c, :table_categories_description cd where c.parent_id = :parent_id and c.categories_id = cd.categories_id and cd.language_id = :language_id order by sort_order, cd.categories_name');
+          $Qcategories-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+          $Qcategories-&gt;bindTable(':table_categories_description', TABLE_CATEGORIES_DESCRIPTION);
+          $Qcategories-&gt;bindInt(':parent_id', $category_links[$i]);
+          $Qcategories-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+          $Qcategories-&gt;execute();
</pre><pre class="diff" id="context">           break; // we've found the deepest category the customer is in
         }
       }
     } else {
</pre><pre class="diff" id="removed">-      $categories_query = tep_db_query("select c.categories_id, cd.categories_name, c.categories_image, c.parent_id from " . TABLE_CATEGORIES . " c, " . TABLE_CATEGORIES_DESCRIPTION . " cd where c.parent_id = '" . (int)$current_category_id . "' and c.categories_id = cd.categories_id and cd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' order by sort_order, cd.categories_name");
</pre><pre class="diff" id="added">+      $Qcategories = $osC_Database-&gt;query('select c.categories_id, cd.categories_name, c.categories_image, c.parent_id from :table_categories c, :table_categories_description cd where c.parent_id = :parent_id and c.categories_id = cd.categories_id and cd.language_id = :language_id order by sort_order, cd.categories_name');
+      $Qcategories-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+      $Qcategories-&gt;bindTable(':table_categories_description', TABLE_CATEGORIES_DESCRIPTION);
+      $Qcategories-&gt;bindInt(':parent_id', $current_category_id);
+      $Qcategories-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+      $Qcategories-&gt;execute();
</pre><pre class="diff" id="context">     }
 
</pre><pre class="diff" id="removed">-    $number_of_categories = tep_db_num_rows($categories_query);
</pre><pre class="diff" id="added">+    $number_of_categories = $Qcategories-&gt;numberOfRows();
</pre><pre class="diff" id="context"> 
     $rows = 0;
</pre><pre class="diff" id="removed">-    while ($categories = tep_db_fetch_array($categories_query)) {
</pre><pre class="diff" id="added">+    while ($Qcategories-&gt;next()) {
</pre><pre class="diff" id="context">       $rows++;
</pre><pre class="diff" id="removed">-      $cPath_new = tep_get_path($categories['categories_id']);
</pre><pre class="diff" id="added">+      $cPath_new = tep_get_path($Qcategories-&gt;valueInt('categories_id'));
</pre><pre class="diff" id="context">       $width = (int)(100 / MAX_DISPLAY_CATEGORIES_PER_ROW) . '%';
</pre><pre class="diff" id="removed">-      echo '                &lt;td align="center" class="smallText" width="' . $width . '" valign="top"&gt;&lt;a href="' . tep_href_link(FILENAME_DEFAULT, $cPath_new) . '"&gt;' . tep_image(DIR_WS_IMAGES . $categories['categories_image'], $categories['categories_name'], SUBCATEGORY_IMAGE_WIDTH, SUBCATEGORY_IMAGE_HEIGHT) . '&lt;br&gt;' . $categories['categories_name'] . '&lt;/a&gt;&lt;/td&gt;' . "\n";
</pre><pre class="diff" id="added">+      echo '                &lt;td align="center" class="smallText" width="' . $width . '" valign="top"&gt;&lt;a href="' . tep_href_link(FILENAME_DEFAULT, $cPath_new) . '"&gt;' . tep_image(DIR_WS_IMAGES . $Qcategories-&gt;value('categories_image'), $Qcategories-&gt;value('categories_name'), SUBCATEGORY_IMAGE_WIDTH, SUBCATEGORY_IMAGE_HEIGHT) . '&lt;br&gt;' . $Qcategories-&gt;value('categories_name') . '&lt;/a&gt;&lt;/td&gt;' . "\n";
</pre><pre class="diff" id="context">       if ((($rows / MAX_DISPLAY_CATEGORIES_PER_ROW) == floor($rows / MAX_DISPLAY_CATEGORIES_PER_ROW)) &amp;&amp; ($rows != $number_of_categories)) {
         echo '              &lt;/tr&gt;' . "\n";
         echo '              &lt;tr&gt;' . "\n";
</pre><pre class="diff"><small id="info">@@ -233,10 +258,13 @@
</small></pre><pre class="diff" id="context">       if (isset($_GET['manufacturers_id']) &amp;&amp; tep_not_null($_GET['manufacturers_id'])) {
         $filterlist_sql = "select distinct c.categories_id as id, cd.categories_name as name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_TO_CATEGORIES . " p2c, " . TABLE_CATEGORIES . " c, " . TABLE_CATEGORIES_DESCRIPTION . " cd where p.products_status = '1' and p.products_id = p2c.products_id and p2c.categories_id = c.categories_id and p2c.categories_id = cd.categories_id and cd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and p.manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "' order by cd.categories_name";
       } else {
</pre><pre class="diff" id="removed">-        $filterlist_sql= "select distinct m.manufacturers_id as id, m.manufacturers_name as name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_TO_CATEGORIES . " p2c, " . TABLE_MANUFACTURERS . " m where p.products_status = '1' and p.manufacturers_id = m.manufacturers_id and p.products_id = p2c.products_id and p2c.categories_id = '" . (int)$current_category_id . "' order by m.manufacturers_name";
</pre><pre class="diff" id="added">+        $filterlist_sql<span id="addedchars">&nbsp;</span>= "select distinct m.manufacturers_id as id, m.manufacturers_name as name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_TO_CATEGORIES . " p2c, " . TABLE_MANUFACTURERS . " m where p.products_status = '1' and p.manufacturers_id = m.manufacturers_id and p.products_id = p2c.products_id and p2c.categories_id = '" . (int)$current_category_id . "' order by m.manufacturers_name";
</pre><pre class="diff" id="context">       }
</pre><pre class="diff" id="removed">-      $filterlist_query = tep_db_query($filterlist_sql);
-      if (tep_db_num_rows($filterlist_query) &gt; 1) {
</pre><pre class="diff" id="added">+
+      $Qfilterlist = $osC_Database-&gt;query($filterlist_sql);
+      $Qfilterlist-&gt;execute();
+
+      if ($Qfilterlist-&gt;numberOfRows() &gt; 1) {
</pre><pre class="diff" id="context">         echo '            &lt;td align="center" class="main"&gt;' . tep_draw_form('filter', FILENAME_DEFAULT, 'get') . TEXT_SHOW . '&amp;nbsp;';
         if (isset($_GET['manufacturers_id']) &amp;&amp; tep_not_null($_GET['manufacturers_id'])) {
           echo osc_draw_hidden_field('manufacturers_id', $_GET['manufacturers_id']);
</pre><pre class="diff"><small id="info">@@ -246,8 +274,9 @@
</small></pre><pre class="diff" id="context">           $options = array(array('id' =&gt; '', 'text' =&gt; TEXT_ALL_MANUFACTURERS));
         }
         echo osc_draw_hidden_field('sort', $_GET['sort']);
</pre><pre class="diff" id="removed">-        while ($filterlist = tep_db_fetch_array($filterlist_query)) {
-          $options[] = array('id' =&gt; $filterlist['id'], 'text' =&gt; $filterlist['name']);
</pre><pre class="diff" id="added">+
+        while ($Qfilterlist-&gt;next()) {
+          $options[] = array('id' =&gt; $Qfilterlist-&gt;valueInt('id'), 'text' =&gt; $Qfilterlist-&gt;value('name'));
</pre><pre class="diff" id="context">         }
         echo osc_draw_pull_down_menu('filter_id', $options, (isset($_GET['filter_id']) ? $_GET['filter_id'] : ''), 'onchange="this.form.submit()"');
         echo '&lt;/form&gt;&lt;/td&gt;' . "\n";
</pre><pre class="diff"><small id="info">@@ -257,16 +286,20 @@
</small></pre><pre class="diff" id="context"> // Get the right image for the top-right
     $image = 'table_background_list.gif';
     if (isset($_GET['manufacturers_id']) &amp;&amp; tep_not_null($_GET['manufacturers_id'])) {
</pre><pre class="diff" id="removed">-      $image = tep_db_query("select manufacturers_image from " . TABLE_MANUFACTURERS . " where manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "'");
-      $image = tep_db_fetch_array($image);
-      $image = $image['manufacturers_image'];
</pre><pre class="diff" id="added">+      $Qimage = $osC_Database-&gt;query('select manufacturers_name as name, manufacturers_image as image from :table_manufacturers where manufacturers_id = :manufacturers_id');
+      $Qimage-&gt;bindTable(':table_manufacturers', TABLE_MANUFACTURERS);
+      $Qimage-&gt;bindInt(':manufacturers_id', $_GET['manufacturers_id']);
+      $Qimage-&gt;execute();
</pre><pre class="diff" id="context">     } elseif ($current_category_id) {
</pre><pre class="diff" id="removed">-      $image = tep_db_query("select categories_image from " . TABLE_CATEGORIES . " where categories_id = '" . (int)$current_category_id . "'");
-      $image = tep_db_fetch_array($image);
-      $image = $image['categories_image'];
</pre><pre class="diff" id="added">+      $Qimage = $osC_Database-&gt;query('select cd.categories_name as name, c.categories_image as image from :table_categories c, :table_categories_description cd where c.categories_id = :categories_id and c.categories_id = cd.categories_id and cd.language_id = :language_id');
+      $Qimage-&gt;bindTable(':table_categories', TABLE_CATEGORIES);
+      $Qimage-&gt;bindTable(':table_categories_description', TABLE_CATEGORIES_DESCRIPTION);
+      $Qimage-&gt;bindInt(':categories_id', $current_category_id);
+      $Qimage-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+      $Qimage-&gt;execute();
</pre><pre class="diff" id="context">     }
 ?&gt;
</pre><pre class="diff" id="removed">-            &lt;td align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . $<span id="removedchars">image,&nbsp;HEADING_TITLE</span>, HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . $<span id="addedchars">Qimage-&gt;value('image'),&nbsp;$Qimage-&gt;value('name')</span>, HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre></div>
<hr /><a name="file8" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>login.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php?rev=1.84&amp;content-type=text/vnd.viewcvs-markup">1.84</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php.diff?r1=1.84&amp;r2=1.85">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/login.php?rev=1.85&amp;content-type=text/vnd.viewcvs-markup">1.85</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.84 -r1.85
--- login.php	2004/07/22 17:23:53	1.84
+++ login.php	2005/03/07 10:04:35	1.85
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -21,26 +21,29 @@
</small></pre><pre class="diff" id="context"> 
   $error = false;
   if (isset($_GET['action']) &amp;&amp; ($_GET['action'] == 'process')) {
</pre><pre class="diff" id="removed">-    $email_address = tep_db_prepare_input($_POST['email_address']);
-    $password = tep_db_prepare_input($_POST['password']);
-
</pre><pre class="diff" id="context"> // Check if email exists
</pre><pre class="diff" id="removed">-    $check_customer_query = tep_db_query("select customers_id, customers_password from " . TABLE_CUSTOMERS . " where customers_email_address = '" . tep_db_input($email_address) . "'");
-    if (!tep_db_num_rows($check_customer_query)) {
</pre><pre class="diff" id="added">+    $Qcheck = $osC_Database-&gt;query('select customers_id, customers_password from :table_customers where customers_email_address = :customers_email_address');
+    $Qcheck-&gt;bindTable(':table_customers', TABLE_CUSTOMERS);
+    $Qcheck-&gt;bindValue(':customers_email_address', $_POST['email_address']);
+    $Qcheck-&gt;execute();
+
+    if ($Qcheck-&gt;numberOfRows() &lt; 1) {
</pre><pre class="diff" id="context">       $error = true;
     } else {
</pre><pre class="diff" id="removed">-      $check_customer = tep_db_fetch_array($check_customer_query);
</pre><pre class="diff" id="context"> // Check that password is good
</pre><pre class="diff" id="removed">-      if (!tep_validate_password($password, $check_customer['customers_password'])) {
</pre><pre class="diff" id="added">+      if (!tep_validate_password($_POST['password'], $Qcheck-&gt;value('customers_password'))) {
</pre><pre class="diff" id="context">         $error = true;
       } else {
         if (SERVICE_SESSION_REGENERATE_ID == 'True') {
           $osC_Session-&gt;recreate();
         }
 
</pre><pre class="diff" id="removed">-        $osC_Customer-&gt;setCustomerData($check_customer['customers_id']);
</pre><pre class="diff" id="added">+        $osC_Customer-&gt;setCustomerData($Qcheck-&gt;valueInt('customers_id'));
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-        tep_db_query("update " . TABLE_CUSTOMERS_INFO . " set customers_info_date_of_last_logon = now(), customers_info_number_of_logons = customers_info_number_of_logons+1 where customers_info_id = '" . (int)$osC_Customer-&gt;id . "'");
</pre><pre class="diff" id="added">+        $Qupdate = $osC_Database-&gt;query('update :table_customers_info set customers_info_date_of_last_logon = now(), customers_info_number_of_logons = customers_info_number_of_logons+1 where customers_info_id = :customers_info_id');
+        $Qupdate-&gt;bindTable(':table_customers_info', TABLE_CUSTOMERS_INFO);
+        $Qupdate-&gt;bindInt(':customers_info_id', $osC_Customer-&gt;id);
+        $Qupdate-&gt;execute();
</pre><pre class="diff" id="context"> 
 // restore cart contents
         $cart-&gt;restore_contents();
</pre></div>
<hr /><a name="file9" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>password_forgotten.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php.diff?r1=1.53&amp;r2=1.54">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/password_forgotten.php?rev=1.54&amp;content-type=text/vnd.viewcvs-markup">1.54</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.53 -r1.54
--- password_forgotten.php	2004/07/22 21:21:36	1.53
+++ password_forgotten.php	2005/03/07 10:04:35	1.54
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,18 +15,21 @@
</small></pre><pre class="diff" id="context">   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PASSWORD_FORGOTTEN);
 
   if (isset($_GET['action']) &amp;&amp; ($_GET['action'] == 'process')) {
</pre><pre class="diff" id="removed">-    $email_address = tep_db_prepare_input($_POST['email_address']);
</pre><pre class="diff" id="added">+    $Qcheck = $osC_Database-&gt;query('select customers_id, customers_firstname, customers_lastname, customers_password from :table_customers where customers_email_address = :customers_email_address');
+    $Qcheck-&gt;bindTable(':table_customers', TABLE_CUSTOMERS);
+    $Qcheck-&gt;bindValue(':customers_email_address', $_POST['email_address']);
+    $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    $check_customer_query = tep_db_query("select customers_firstname, customers_lastname, customers_password, customers_id from " . TABLE_CUSTOMERS . " where customers_email_address = '" . tep_db_input($email_address) . "'");
-    if (tep_db_num_rows($check_customer_query)) {
-      $check_customer = tep_db_fetch_array($check_customer_query);
-
</pre><pre class="diff" id="added">+    if ($Qcheck-&gt;numberOfRows()) {
</pre><pre class="diff" id="context">       $new_password = tep_create_random_value(ACCOUNT_PASSWORD);
</pre><pre class="diff" id="removed">-      $crypted_password = tep_encrypt_password($new_password);
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-      tep_db_query("update " . TABLE_CUSTOMERS . " set customers_password = '" . tep_db_input($crypted_password) . "' where customers_id = '" . (int)$check_customer['customers_id'] . "'");
</pre><pre class="diff" id="added">+      $Qupdate = $osC_Database-&gt;query('update :table_customers set customers_password = :customers_password where customers_id = :customers_id');
+      $Qupdate-&gt;bindTable(':table_customers', TABLE_CUSTOMERS);
+      $Qupdate-&gt;bindValue(':customers_password', tep_encrypt_password($new_password));
+      $Qupdate-&gt;bindInt(':customers_id', $Qcheck-&gt;valueInt('customers_id'));
+      $Qupdate-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-      tep_mail($check_customer['customers_firstname'] . ' ' . $check_customer['customers_lastname'], $email_address, EMAIL_PASSWORD_REMINDER_SUBJECT, sprintf(EMAIL_PASSWORD_REMINDER_BODY, $new_password), STORE_OWNER, STORE_OWNER_EMAIL_ADDRESS);
</pre><pre class="diff" id="added">+      tep_mail($Qcheck-&gt;valueProtected('customers_firstname') . ' ' . $Qcheck-&gt;valueProtected('customers_lastname'), $_POST['email_address'], EMAIL_PASSWORD_REMINDER_SUBJECT, sprintf(EMAIL_PASSWORD_REMINDER_BODY, $new_password), STORE_OWNER, STORE_OWNER_EMAIL_ADDRESS);
</pre><pre class="diff" id="context"> 
       $messageStack-&gt;add_session('login', SUCCESS_PASSWORD_SENT, 'success');
 
</pre></div>
<hr /><a name="file10" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>popup_image.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php?rev=1.19&amp;content-type=text/vnd.viewcvs-markup">1.19</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php.diff?r1=1.19&amp;r2=1.20">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/popup_image.php?rev=1.20&amp;content-type=text/vnd.viewcvs-markup">1.20</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.19 -r1.20
--- popup_image.php	2003/11/17 21:00:43	1.19
+++ popup_image.php	2005/03/07 10:04:36	1.20
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -14,14 +14,18 @@
</small></pre><pre class="diff" id="context"> 
   $navigation-&gt;remove_current_page();
 
</pre><pre class="diff" id="removed">-  $products_query = tep_db_query("select pd.products_name, p.products_image from " . TABLE_PRODUCTS . " p left join " . TABLE_PRODUCTS_DESCRIPTION . " pd on p.products_id = pd.products_id where p.products_status = '1' and p.products_id = '" . (int)$_GET['pID'] . "' and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-  $products = tep_db_fetch_array($products_query);
</pre><pre class="diff" id="added">+  $Qproducts = $osC_Database-&gt;query('select pd.products_name, p.products_image from :table_products p left join :table_products_description pd on p.products_id = pd.products_id where p.products_status = 1 and p.products_id = :products_id and pd.language_id = :language_id');
+  $Qproducts-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qproducts-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qproducts-&gt;bindInt(':products_id', $_GET['pID']);
+  $Qproducts-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qproducts-&gt;execute();
</pre><pre class="diff" id="context"> ?&gt;
 &lt;!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"&gt;
 &lt;html &lt;?php echo HTML_PARAMS; ?&gt;&gt;
 &lt;head&gt;
 &lt;meta http-equiv="Content-Type" content="text/html; charset=&lt;?php echo CHARSET; ?&gt;"&gt;
</pre><pre class="diff" id="removed">-&lt;title&gt;&lt;?php echo $products['products_name']; ?&gt;&lt;/title&gt;
</pre><pre class="diff" id="added">+&lt;title&gt;&lt;?php echo $Qproducts-&gt;value('products_name'); ?&gt;&lt;/title&gt;
</pre><pre class="diff" id="context"> &lt;base href="&lt;?php echo (($request_type == 'SSL') ? HTTPS_SERVER : HTTP_SERVER) . DIR_WS_CATALOG; ?&gt;"&gt;
 &lt;script language="javascript"&gt;&lt;!--
 var i=0;
</pre><pre class="diff"><small id="info">@@ -33,7 +37,7 @@
</small></pre><pre class="diff" id="context"> //--&gt;&lt;/script&gt;
 &lt;/head&gt;
 &lt;body onload="resize();"&gt;
</pre><pre class="diff" id="removed">-&lt;?php echo tep_image(DIR_WS_IMAGES . $products['products_image'], $products['products_name']); ?&gt;
</pre><pre class="diff" id="added">+&lt;?php echo tep_image(DIR_WS_IMAGES . $Qproducts-&gt;value('products_image'), $Qproducts-&gt;value('products_name')); ?&gt;
</pre><pre class="diff" id="context"> &lt;/body&gt;
 &lt;/html&gt;
 &lt;?php require('includes/application_bottom.php'); ?&gt;
</pre></div>
<hr /><a name="file11" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>product_info.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php?rev=1.106&amp;content-type=text/vnd.viewcvs-markup">1.106</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php.diff?r1=1.106&amp;r2=1.107">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_info.php?rev=1.107&amp;content-type=text/vnd.viewcvs-markup">1.107</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.106 -r1.107
--- product_info.php	2004/11/03 09:00:49	1.106
+++ product_info.php	2005/03/07 10:04:36	1.107
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -14,8 +14,12 @@
</small></pre><pre class="diff" id="context"> 
   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PRODUCT_INFO);
 
</pre><pre class="diff" id="removed">-  $product_check_query = tep_db_query("select count(*) as total from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_status = '1' and p.products_id = '" . (int)$_GET['products_id'] . "' and pd.products_id = p.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-  $product_check = tep_db_fetch_array($product_check_query);
</pre><pre class="diff" id="added">+  $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_products p, :table_products_description pd where p.products_status = 1 and p.products_id = :products_id and pd.products_id = p.products_id and pd.language_id = :language_id');
+  $Qcheck-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qcheck-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qcheck-&gt;bindInt(':products_id', $_GET['products_id']);
+  $Qcheck-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> ?&gt;
 &lt;!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN"&gt;
 &lt;html &lt;?php echo HTML_PARAMS; ?&gt;&gt;
</pre><pre class="diff"><small id="info">@@ -46,7 +50,7 @@
</small></pre><pre class="diff" id="context"> &lt;!-- body_text //--&gt;
     &lt;td width="100%" valign="top"&gt;&lt;?php echo tep_draw_form('cart_quantity', tep_href_link(FILENAME_PRODUCT_INFO, tep_get_all_get_params(array('action')) . 'action=add_product')); ?&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="0"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if ($product_check['total'] &lt; 1) {
</pre><pre class="diff" id="added">+  if ($Qcheck-&gt;valueInt('total') &lt; 1) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;?php new infoBox(array(array('text' =&gt; TEXT_PRODUCT_NOT_FOUND))); ?&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -69,21 +73,29 @@
</small></pre><pre class="diff" id="context">       &lt;/tr&gt;
 &lt;?php
   } else {
</pre><pre class="diff" id="removed">-    $product_info_query = tep_db_query("select p.products_id, pd.products_name, pd.products_description, p.products_model, p.products_quantity, p.products_image, pd.products_url, p.products_price, p.products_tax_class_id, p.products_date_added, p.products_date_available, p.manufacturers_id from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_status = '1' and p.products_id = '" . (int)$_GET['products_id'] . "' and pd.products_id = p.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-    $product_info = tep_db_fetch_array($product_info_query);
</pre><pre class="diff" id="added">+    $Qproduct = $osC_Database-&gt;query('select p.products_id, pd.products_name, pd.products_description, p.products_model, p.products_quantity, p.products_image, pd.products_url, p.products_price, p.products_tax_class_id, p.products_date_added, p.products_date_available, p.manufacturers_id from :table_products p, :table_products_description pd where p.products_status = 1 and p.products_id = :products_id and pd.products_id = p.products_id and pd.language_id = :language_id');
+    $Qproduct-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+    $Qproduct-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+    $Qproduct-&gt;bindInt(':products_id', $_GET['products_id']);
+    $Qproduct-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+    $Qproduct-&gt;execute();
+
+    $Qupdate = $osC_Database-&gt;query('update :table_products_description set products_viewed = products_viewed+1 where products_id = :products_id and language_id = :language_id');
+    $Qupdate-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+    $Qupdate-&gt;bindInt(':products_id', $_GET['products_id']);
+    $Qupdate-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+    $Qupdate-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    tep_db_query("update " . TABLE_PRODUCTS_DESCRIPTION . " set products_viewed = products_viewed+1 where products_id = '" . (int)$_GET['products_id'] . "' and language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-
-    if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($product_info['products_id'])) ) {
-      $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $product_info['products_tax_class_id']) . '&lt;/span&gt;';
</pre><pre class="diff" id="added">+    if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($Qproduct-&gt;valueInt('products_id'))) ) {
+      $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qproduct-&gt;value('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/span&gt;';
</pre><pre class="diff" id="context">     } else {
</pre><pre class="diff" id="removed">-      $products_price = $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']);
</pre><pre class="diff" id="added">+      $products_price = $osC_Currencies-&gt;displayPrice($Qproduct-&gt;value('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id'));
</pre><pre class="diff" id="context">     }
 
</pre><pre class="diff" id="removed">-    if (tep_not_null($product_info['products_model'])) {
-      $products_name = $product_info['products_name'] . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $product_info['products_model'] . ']&lt;/span&gt;';
</pre><pre class="diff" id="added">+    if (tep_not_null($Qproduct-&gt;value('products_model'))) {
+      $products_name = $Qproduct-&gt;value('products_name') . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $Qproduct-&gt;value('products_model') . ']&lt;/span&gt;';
</pre><pre class="diff" id="context">     } else {
</pre><pre class="diff" id="removed">-      $products_name = $product_info['products_name'];
</pre><pre class="diff" id="added">+      $products_name = $Qproduct-&gt;value('products_name');
</pre><pre class="diff" id="context">     }
 ?&gt;
       &lt;tr&gt;
</pre><pre class="diff"><small id="info">@@ -100,16 +112,16 @@
</small></pre><pre class="diff" id="context">       &lt;tr&gt;
         &lt;td class="main"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-    if (tep_not_null($product_info['products_image'])) {
</pre><pre class="diff" id="added">+    if (tep_not_null($Qproduct-&gt;value('products_image'))) {
</pre><pre class="diff" id="context"> ?&gt;
           &lt;table border="0" cellspacing="0" cellpadding="2" align="right"&gt;
             &lt;tr&gt;
               &lt;td align="center" class="smallText"&gt;
 &lt;script language="javascript"&gt;&lt;!--
</pre><pre class="diff" id="removed">-document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $product_info['products_id']) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], addslashes($product_info['products_name']), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="added">+document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $Qproduct-&gt;valueInt('products_id')) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), addslashes($Qproduct-&gt;value('products_name')), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="context"> //--&gt;&lt;/script&gt;
 &lt;noscript&gt;
</pre><pre class="diff" id="removed">-&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $product_info['products_image']) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], $product_info['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="added">+&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image')) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), $Qproduct-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="context"> &lt;/noscript&gt;
               &lt;/td&gt;
             &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -117,37 +129,57 @@
</small></pre><pre class="diff" id="context"> &lt;?php
     }
 ?&gt;
</pre><pre class="diff" id="removed">-          &lt;p&gt;&lt;?php echo stripslashes($product_info['products_description']); ?&gt;&lt;/p&gt;
</pre><pre class="diff" id="added">+          &lt;p&gt;&lt;?php echo $Qproduct-&gt;value('products_description'); ?&gt;&lt;/p&gt;
</pre><pre class="diff" id="context"> &lt;?php
</pre><pre class="diff" id="removed">-    $products_attributes_query = tep_db_query("select count(*) as total from " . TABLE_PRODUCTS_OPTIONS . " popt, " . TABLE_PRODUCTS_ATTRIBUTES . " patrib where patrib.products_id='" . (int)$_GET['products_id'] . "' and patrib.options_id = popt.products_options_id and popt.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-    $products_attributes = tep_db_fetch_array($products_attributes_query);
-    if ($products_attributes['total'] &gt; 0) {
</pre><pre class="diff" id="added">+    $Qattributes = $osC_Database-&gt;query('select count(*) as total from :table_products_options popt, :table_products_attributes patrib where patrib.products_id = :products_id and patrib.options_id = popt.products_options_id and popt.language_id = :language_id');
+    $Qattributes-&gt;bindTable(':table_products_options', TABLE_PRODUCTS_OPTIONS);
+    $Qattributes-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+    $Qattributes-&gt;bindInt(':products_id', $_GET['products_id']);
+    $Qattributes-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+    $Qattributes-&gt;execute();
+
+    if ($Qattributes-&gt;valueInt('total') &gt; 0) {
</pre><pre class="diff" id="context"> ?&gt;
           &lt;table border="0" cellspacing="0" cellpadding="2"&gt;
             &lt;tr&gt;
               &lt;td class="main" colspan="2"&gt;&lt;?php echo TEXT_PRODUCT_OPTIONS; ?&gt;&lt;/td&gt;
             &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-      $products_options_name_query = tep_db_query("select distinct popt.products_options_id, popt.products_options_name from " . TABLE_PRODUCTS_OPTIONS . " popt, " . TABLE_PRODUCTS_ATTRIBUTES . " patrib where patrib.products_id='" . (int)$_GET['products_id'] . "' and patrib.options_id = popt.products_options_id and popt.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' order by popt.products_options_name");
-      while ($products_options_name = tep_db_fetch_array($products_options_name_query)) {
</pre><pre class="diff" id="added">+      $Qoptions = $osC_Database-&gt;query('select distinct popt.products_options_id, popt.products_options_name from :table_products_options popt, :table_products_attributes patrib where patrib.products_id = :products_id and patrib.options_id = popt.products_options_id and popt.language_id = :language_id order by popt.products_options_name');
+      $Qoptions-&gt;bindTable(':table_products_options', TABLE_PRODUCTS_OPTIONS);
+      $Qoptions-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+      $Qoptions-&gt;bindInt(':products_id', $_GET['products_id']);
+      $Qoptions-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+      $Qoptions-&gt;execute();
+
+      while ($Qoptions-&gt;next()) {
</pre><pre class="diff" id="context">         $products_options_array = array();
</pre><pre class="diff" id="removed">-        $products_options_query = tep_db_query("select pov.products_options_values_id, pov.products_options_values_name, pa.options_values_price, pa.price_prefix from " . TABLE_PRODUCTS_ATTRIBUTES . " pa, " . TABLE_PRODUCTS_OPTIONS_VALUES . " pov where pa.products_id = '" . (int)$_GET['products_id'] . "' and pa.options_id = '" . (int)$products_options_name['products_options_id'] . "' and pa.options_values_id = pov.products_options_values_id and pov.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-        while ($products_options = tep_db_fetch_array($products_options_query)) {
-          $products_options_array[] = array('id' =&gt; $products_options['products_options_values_id'], 'text' =&gt; $products_options['products_options_values_name']);
-          if ($products_options['options_values_price'] != '0') {
-            $products_options_array[sizeof($products_options_array)-1]['text'] .= ' (' . $products_options['price_prefix'] . $osC_Currencies-&gt;displayPrice($products_options['options_values_price'], $product_info['products_tax_class_id']) .') ';
</pre><pre class="diff" id="added">+
+        $Qvalues = $osC_Database-&gt;query('select pov.products_options_values_id, pov.products_options_values_name, pa.options_values_price, pa.price_prefix from :table_products_attributes pa, :table_products_options_values pov where pa.products_id = :products_id and pa.options_id = :options_id and pa.options_values_id = pov.products_options_values_id and pov.language_id = :language_id');
+        $Qvalues-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+        $Qvalues-&gt;bindTable(':table_products_options_values', TABLE_PRODUCTS_OPTIONS_VALUES);
+        $Qvalues-&gt;bindInt(':products_id', $_GET['products_id']);
+        $Qvalues-&gt;bindInt(':options_id', $Qoptions-&gt;valueInt('products_options_id'));
+        $Qvalues-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+        $Qvalues-&gt;execute();
+
+        while ($Qvalues-&gt;next()) {
+          $products_options_array[] = array('id' =&gt; $Qvalues-&gt;valueInt('products_options_values_id'), 'text' =&gt; $Qvalues-&gt;value('products_options_values_name'));
+
+          if ($Qvalues-&gt;value('options_values_price') != '0') {
+            $products_options_array[sizeof($products_options_array)-1]['text'] .= ' (' . $Qvalues-&gt;value('price_prefix') . $osC_Currencies-&gt;displayPrice($Qvalues-&gt;value('options_values_price'), $Qproduct-&gt;valueInt('products_tax_class_id')) .') ';
</pre><pre class="diff" id="context">           }
         }
 
</pre><pre class="diff" id="removed">-        if (isset($cart-&gt;contents[$_GET['products_id']]['attributes'][$products_options_name['products_options_id']])) {
-          $selected_attribute = $cart-&gt;contents[$_GET['products_id']]['attributes'][$products_options_name['products_options_id']];
</pre><pre class="diff" id="added">+        if (isset($cart-&gt;contents[$_GET['products_id']]['attributes'][$Qoptions-&gt;valueInt('products_options_id')])) {
+          $selected_attribute = $cart-&gt;contents[$_GET['products_id']]['attributes'][$Qoptions-&gt;valueInt('products_options_id')];
</pre><pre class="diff" id="context">         } else {
           $selected_attribute = false;
         }
 ?&gt;
             &lt;tr&gt;
</pre><pre class="diff" id="removed">-              &lt;td class="main"&gt;&lt;?php echo $products_options_name['products_options_name'] . ':'; ?&gt;&lt;/td&gt;
-              &lt;td class="main"&gt;&lt;?php echo osc_draw_pull_down_menu('id[' . $products_options_name['products_options_id'] . ']', $products_options_array, $selected_attribute); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+              &lt;td class="main"&gt;&lt;?php echo $Qoptions-&gt;value('products_options_name') . ':'; ?&gt;&lt;/td&gt;
+              &lt;td class="main"&gt;&lt;?php echo osc_draw_pull_down_menu('id[' . $Qoptions-&gt;valueInt('products_options_id') . ']', $products_options_array, $selected_attribute); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">             &lt;/tr&gt;
 &lt;?php
       }
</pre><pre class="diff"><small id="info">@@ -163,12 +195,15 @@
</small></pre><pre class="diff" id="context">       &lt;/tr&gt;
 &lt;?php
     if ($osC_Services-&gt;isStarted('reviews')) {
</pre><pre class="diff" id="removed">-      $reviews_query = tep_db_query("select count(*) as count from " . TABLE_REVIEWS . " where products_id = '" . (int)$_GET['products_id'] . "'");
-      $reviews = tep_db_fetch_array($reviews_query);
-      if ($reviews['count'] &gt; 0) {
</pre><pre class="diff" id="added">+      $Qreviews = $osC_Database-&gt;query('select count(*) as count from :table_reviews where products_id = :products_id');
+      $Qreviews-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+      $Qreviews-&gt;bindInt(':products_id', $_GET['products_id']);
+      $Qreviews-&gt;execute();
+
+      if ($Qreviews-&gt;valueInt('count') &gt; 0) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
</pre><pre class="diff" id="removed">-        &lt;td class="main"&gt;&lt;?php echo TEXT_CURRENT_REVIEWS . ' ' . $<span id="removedchars">reviews['count']</span>; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+        &lt;td class="main"&gt;&lt;?php echo TEXT_CURRENT_REVIEWS . ' ' . $<span id="addedchars">Qreviews-&gt;valueInt('count')</span>; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">       &lt;/tr&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -176,10 +211,11 @@
</small></pre><pre class="diff" id="context"> &lt;?php
       }
     }
</pre><pre class="diff" id="removed">-    if (tep_not_null($product_info['products_url'])) {
</pre><pre class="diff" id="added">+
+    if (tep_not_null($Qproduct-&gt;value('products_url'))) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
</pre><pre class="diff" id="removed">-        &lt;td class="main"&gt;&lt;?php echo sprintf(TEXT_MORE_INFORMATION, tep_href_link(FILENAME_REDIRECT, 'action=url&amp;goto=' . urlencode($<span id="removedchars">product_info['products_url']</span>), 'NONSSL', true, false)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+        &lt;td class="main"&gt;&lt;?php echo sprintf(TEXT_MORE_INFORMATION, tep_href_link(FILENAME_REDIRECT, 'action=url&amp;goto=' . urlencode($<span id="addedchars">Qproduct-&gt;value('products_url')</span>), 'NONSSL', true, false)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">       &lt;/tr&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -187,16 +223,16 @@
</small></pre><pre class="diff" id="context"> &lt;?php
     }
 
</pre><pre class="diff" id="removed">-    if ($product_info['products_date_available'] &gt; date('Y-m-d H:i:s')) {
</pre><pre class="diff" id="added">+    if ($Qproduct-&gt;value('products_date_available') &gt; date('Y-m-d H:i:s')) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
</pre><pre class="diff" id="removed">-        &lt;td align="center" class="smallText"&gt;&lt;?php echo sprintf(TEXT_DATE_AVAILABLE, tep_date_long($<span id="removedchars">product_info['products_date_available']</span>)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+        &lt;td align="center" class="smallText"&gt;&lt;?php echo sprintf(TEXT_DATE_AVAILABLE, tep_date_long($<span id="addedchars">Qproduct-&gt;value('products_date_available')</span>)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">       &lt;/tr&gt;
 &lt;?php
     } else {
 ?&gt;
       &lt;tr&gt;
</pre><pre class="diff" id="removed">-        &lt;td align="center" class="smallText"&gt;&lt;?php echo sprintf(TEXT_DATE_ADDED, tep_date_long($<span id="removedchars">product_info['products_date_added']</span>)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+        &lt;td align="center" class="smallText"&gt;&lt;?php echo sprintf(TEXT_DATE_ADDED, tep_date_long($<span id="addedchars">Qproduct-&gt;value('products_date_added')</span>)); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">       &lt;/tr&gt;
 &lt;?php
     }
</pre><pre class="diff"><small id="info">@@ -211,13 +247,13 @@
</small></pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                 &lt;td class="main"&gt;
</pre><pre class="diff" id="removed">-&lt;?php<span id="removedchars">&nbsp;</span>
</pre><pre class="diff" id="added">+&lt;?php
</pre><pre class="diff" id="context">   if ($osC_Services-&gt;isStarted('reviews')) {
</pre><pre class="diff" id="removed">-    echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params()) . '"&gt;' . tep_image_button('button_reviews.gif', IMAGE_BUTTON_REVIEWS) . '&lt;/a&gt;';<span id="removedchars">&nbsp;</span>
</pre><pre class="diff" id="added">+    echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params()) . '"&gt;' . tep_image_button('button_reviews.gif', IMAGE_BUTTON_REVIEWS) . '&lt;/a&gt;';
</pre><pre class="diff" id="context">   }
 ?&gt;
                 &lt;/td&gt;
</pre><pre class="diff" id="removed">-                &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_hidden_field('products_id', $<span id="removedchars">product_info['products_id']</span>) . tep_image_submit('button_in_cart.gif', IMAGE_BUTTON_IN_CART); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                &lt;td class="main" align="right"&gt;&lt;?php echo osc_draw_hidden_field('products_id', $<span id="addedchars">Qproduct-&gt;valueInt('products_id')</span>) . tep_image_submit('button_in_cart.gif', IMAGE_BUTTON_IN_CART); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                 &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
               &lt;/tr&gt;
             &lt;/table&gt;&lt;/td&gt;
</pre></div>
<hr /><a name="file12" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>product_reviews.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php?rev=1.55&amp;content-type=text/vnd.viewcvs-markup">1.55</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php.diff?r1=1.55&amp;r2=1.56">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews.php?rev=1.56&amp;content-type=text/vnd.viewcvs-markup">1.56</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.55 -r1.56
--- product_reviews.php	2004/11/03 09:00:50	1.55
+++ product_reviews.php	2005/03/07 10:04:36	1.56
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,24 +15,32 @@
</small></pre><pre class="diff" id="context">   if (!$osC_Services-&gt;isStarted('reviews')) {
     tep_redirect(tep_href_link(FILENAME_DEFAULT));
   }
</pre><pre class="diff" id="removed">-    
-  $product_info_query = tep_db_query("select p.products_id, p.products_model, p.products_image, p.products_price, p.products_tax_class_id, pd.products_name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_id = '" . (int)$_GET['products_id'] . "' and p.products_status = '1' and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-  if (!tep_db_num_rows($product_info_query)) {
</pre><pre class="diff" id="added">+
+  $Qproduct = $osC_Database-&gt;query('select p.products_id, p.products_model, p.products_image, p.products_price, p.products_tax_class_id, pd.products_name from :table_products p, :table_products_description pd where p.products_id = :products_id and p.products_status = 1 and p.products_id = pd.products_id and pd.language_id = :language_id');
+  $Qproduct-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qproduct-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qproduct-&gt;bindInt(':products_id', $_GET['products_id']);
+  $Qproduct-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qproduct-&gt;execute();
+
+  if ($Qproduct-&gt;numberOfRows() &lt; 1) {
</pre><pre class="diff" id="context">     tep_redirect(tep_href_link(FILENAME_REVIEWS));
</pre><pre class="diff" id="removed">-  } else {
-    $product_info = tep_db_fetch_array($product_info_query);
</pre><pre class="diff" id="context">   }
 
</pre><pre class="diff" id="removed">-  if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($product_info['products_id'])) ) {
-    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $product_info['products_tax_class_id']) . '&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($Qproduct-&gt;valueInt('products_id'))) ) {
+    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qproduct-&gt;value('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_price = $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']);
</pre><pre class="diff" id="added">+    $products_price = $osC_Currencies-&gt;displayPrice($Qproduct-&gt;value('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id'));
</pre><pre class="diff" id="context">   }
 
</pre><pre class="diff" id="removed">-  if (tep_not_null($product_info['products_model'])) {
-    $products_name = $product_info['products_name'] . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $product_info['products_model'] . ']&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if (tep_not_null($Qproduct-&gt;value('products_model'))) {
+    $products_name = $Qproduct-&gt;value('products_name') . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $Qproduct-&gt;value('products_model') . ']&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_name = $product_info['products_name'];
</pre><pre class="diff" id="added">+    $products_name = $Qproduct-&gt;value('products_name');
+  }
+
+  if (!isset($_GET['page']) || (isset($_GET['page']) &amp;&amp; !is_numeric($_GET['page']))) {
+    $_GET['page'] = 1;
</pre><pre class="diff" id="context">   }
 
   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PRODUCT_REVIEWS);
</pre><pre class="diff"><small id="info">@@ -95,17 +103,21 @@
</small></pre><pre class="diff" id="context">           &lt;tr&gt;
             &lt;td valign="top"&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  $reviews_query_raw = "select r.reviews_id, left(r.reviews_text, 100) as reviews_text, r.reviews_rating, r.date_added, customers_name from " . TABLE_REVIEWS . " r where r.products_id = '" . (int)$product_info['products_id'] . "' and languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and r.reviews_status = 1 order by reviews_id desc";
-  $reviews_split = new splitPageResults($reviews_query_raw, MAX_DISPLAY_NEW_REVIEWS);
</pre><pre class="diff" id="added">+  $Qreviews = $osC_Database-&gt;query('select r.reviews_id, left(r.reviews_text, 100) as reviews_text, r.reviews_rating, r.date_added, customers_name from :table_reviews r where r.products_id = :products_id and languages_id = :languages_id and r.reviews_status = 1 order by reviews_id desc');
+  $Qreviews-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+  $Qreviews-&gt;bindInt(':products_id', $Qproduct-&gt;valueInt('products_id'));
+  $Qreviews-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+  $Qreviews-&gt;setBatchLimit($_GET['page'], MAX_DISPLAY_NEW_REVIEWS);
+  $Qreviews-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if ($reviews_split-&gt;number_of_rows &gt; 0) {
</pre><pre class="diff" id="added">+  if ($Qreviews-&gt;numberOfRows() &gt; 0) {
</pre><pre class="diff" id="context">     if ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3')) {
 ?&gt;
               &lt;tr&gt;
                 &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="smallText"&gt;&lt;?php echo $reviews_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
-                    &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $reviews_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
+                    &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksPullDown('page', tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -115,14 +127,13 @@
</small></pre><pre class="diff" id="context"> &lt;?php
     }
 
</pre><pre class="diff" id="removed">-    $reviews_query = tep_db_query($reviews_split-&gt;sql_query);
-    while ($reviews = tep_db_fetch_array($reviews_query)) {
</pre><pre class="diff" id="added">+    while ($Qreviews-&gt;next()) {
</pre><pre class="diff" id="context"> ?&gt;
               &lt;tr&gt;
                 &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $product_info['products_id'] . '&amp;reviews_id=' . $reviews['reviews_id']) . '"&gt;&lt;u&gt;&lt;b&gt;' . sprintf(TEXT_REVIEW_BY, tep_output_string_protected($reviews['customers_name'])) . '&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;'; ?&gt;&lt;/td&gt;
-                    &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($reviews['date_added'])); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $Qproduct-&gt;valueInt('products_id') . '&amp;reviews_id=' . $Qreviews-&gt;valueInt('reviews_id')) . '"&gt;&lt;u&gt;&lt;b&gt;' . sprintf(TEXT_REVIEW_BY, $Qreviews-&gt;valueProtected('customers_name')) . '&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;'; ?&gt;&lt;/td&gt;
+                    &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($Qreviews-&gt;value('date_added'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -132,7 +143,7 @@
</small></pre><pre class="diff" id="context">                     &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                       &lt;tr&gt;
                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                        &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string(tep_output_string_protected($reviews['reviews_text']), 60, '-&lt;br&gt;') . ((strlen($reviews['reviews_text']) &gt;= 100) ? '..' : '') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $reviews['reviews_rating'] . '.gif', sprintf(TEXT_OF_5_STARS, $reviews['reviews_rating'])), sprintf(TEXT_OF_5_STARS, $reviews['reviews_rating'])) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                        &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string($Qreviews-&gt;valueProtected('reviews_text'), 60, '-&lt;br&gt;') . ((strlen($Qreviews-&gt;value('reviews_text')) &gt;= 100) ? '..' : '') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $Qreviews-&gt;valueInt('reviews_rating') . '.gif', sprintf(TEXT_OF_5_STARS, $Qreviews-&gt;valueInt('reviews_rating'))), sprintf(TEXT_OF_5_STARS, $Qreviews-&gt;valueInt('reviews_rating'))) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                         &lt;td width="10" align="right"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                       &lt;/tr&gt;
                     &lt;/table&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -157,13 +168,13 @@
</small></pre><pre class="diff" id="context"> &lt;?php
   }
 
</pre><pre class="diff" id="removed">-  if (($<span id="removedchars">reviews_split-&gt;number_of_rows</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+  if (($<span id="addedchars">Qreviews-&gt;numberOfRows()</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="context"> ?&gt;
               &lt;tr&gt;
                 &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="smallText"&gt;&lt;?php echo $reviews_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
-                    &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $reviews_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
+                    &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksPullDown('page', tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -180,7 +191,7 @@
</small></pre><pre class="diff" id="context">                       &lt;tr&gt;
                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                         &lt;td class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, tep_get_all_get_params()) . '"&gt;' . tep_image_button('button_back.gif', IMAGE_BUTTON_BACK) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                        &lt;td class="main" align="right"&gt;<span id="removedchars">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
</pre><pre class="diff" id="added">+                        &lt;td class="main" align="right"&gt;
</pre><pre class="diff" id="context"> &lt;?php
   if ($osC_Reviews-&gt;is_enabled === true) {
     echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_WRITE, tep_get_all_get_params()) . '"&gt;' . tep_image_button('button_write_review.gif', IMAGE_BUTTON_WRITE_REVIEW) . '&lt;/a&gt;';
</pre><pre class="diff"><small id="info">@@ -198,13 +209,13 @@
</small></pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td align="center" class="smallText"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if (tep_not_null($product_info['products_image'])) {
</pre><pre class="diff" id="added">+  if (tep_not_null($Qproduct-&gt;value('products_image'))) {
</pre><pre class="diff" id="context"> ?&gt;
 &lt;script language="javascript"&gt;&lt;!--
</pre><pre class="diff" id="removed">-document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $product_info['products_id']) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], addslashes($product_info['products_name']), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="added">+document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $Qproduct-&gt;valueInt('products_id')) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), addslashes($Qproduct-&gt;value('products_name')), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="context"> //--&gt;&lt;/script&gt;
 &lt;noscript&gt;
</pre><pre class="diff" id="removed">-&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $product_info['products_image']) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], $product_info['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="added">+&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image')) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), $Qproduct-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="context"> &lt;/noscript&gt;
 &lt;?php
   }
</pre></div>
<hr /><a name="file13" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>product_reviews_info.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php?rev=1.56&amp;content-type=text/vnd.viewcvs-markup">1.56</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php.diff?r1=1.56&amp;r2=1.57">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_info.php?rev=1.57&amp;content-type=text/vnd.viewcvs-markup">1.57</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.56 -r1.57
--- product_reviews_info.php	2004/11/03 09:00:50	1.56
+++ product_reviews_info.php	2005/03/07 10:04:36	1.57
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,33 +15,46 @@
</small></pre><pre class="diff" id="context">   if (!$osC_Services-&gt;isStarted('reviews')) {
     tep_redirect(tep_href_link(FILENAME_DEFAULT));
   }
</pre><pre class="diff" id="removed">-  
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">   if (isset($_GET['reviews_id']) &amp;&amp; tep_not_null($_GET['reviews_id']) &amp;&amp; isset($_GET['products_id']) &amp;&amp; tep_not_null($_GET['products_id'])) {
</pre><pre class="diff" id="removed">-    $review_check_query = tep_db_query("select count(*) as total from " . TABLE_REVIEWS . " r where r.reviews_id = '" . (int)$_GET['reviews_id'] . "' and r.products_id = '" . (int)$_GET['products_id'] . "' and r.languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-    $review_check = tep_db_fetch_array($review_check_query);
</pre><pre class="diff" id="added">+    $Qcheck = $osC_Database-&gt;query('select count(*) as total from :table_reviews where reviews_id = :reviews_id and products_id = :products_id and languages_id = :languages_id');
+    $Qcheck-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+    $Qcheck-&gt;bindInt(':reviews_id', $_GET['reviews_id']);
+    $Qcheck-&gt;bindInt(':products_id', $_GET['products_id']);
+    $Qcheck-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+    $Qcheck-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    if ($review_check['total'] &lt; 1) {
</pre><pre class="diff" id="added">+    if ($Qcheck-&gt;valueInt('total') &lt; 1) {
</pre><pre class="diff" id="context">       tep_redirect(tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params(array('reviews_id'))));
     }
   } else {
     tep_redirect(tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params(array('reviews_id'))));
   }
</pre><pre class="diff" id="removed">-
-  tep_db_query("update " . TABLE_REVIEWS . " set reviews_read = reviews_read+1 where reviews_id = '" . (int)$_GET['reviews_id'] . "'");
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  $review_query = tep_db_query("select r.reviews_text, r.reviews_rating, r.reviews_id, r.customers_name, r.date_added, r.reviews_read, p.products_id, p.products_price, p.products_tax_class_id, p.products_image, p.products_model, pd.products_name from " . TABLE_REVIEWS . " r, " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where r.reviews_id = '" . (int)$_GET['reviews_id'] . "' and r.languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and r.products_id = p.products_id and p.products_status = '1' and p.products_id = pd.products_id and pd.language_id = '". (int)$osC_Session-&gt;value('languages_id') . "' and r.reviews_status = 1");
-  $review = tep_db_fetch_array($review_query);
</pre><pre class="diff" id="added">+  $Qupdate = $osC_Database-&gt;query('update :table_reviews set reviews_read = reviews_read+1 where reviews_id = :reviews_id');
+  $Qupdate-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+  $Qupdate-&gt;bindInt(':reviews_id', $_GET['reviews_id']);
+  $Qupdate-&gt;execute();
+
+  $Qreview = $osC_Database-&gt;query('select r.reviews_text, r.reviews_rating, r.reviews_id, r.customers_name, r.date_added, r.reviews_read, p.products_id, p.products_price, p.products_tax_class_id, p.products_image, p.products_model, pd.products_name from :table_reviews r, :table_products p, :table_products_description pd where r.reviews_id = :reviews_id and r.languages_id = :languages_id and r.products_id = p.products_id and p.products_status = 1 and p.products_id = pd.products_id and pd.language_id = :language_id and r.reviews_status = 1');
+  $Qreview-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+  $Qreview-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qreview-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qreview-&gt;bindInt(':reviews_id', $_GET['reviews_id']);
+  $Qreview-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+  $Qreview-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qreview-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($review['products_id'])) ) {
-    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($review['products_price'], $review['products_tax_class_id']) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $review['products_tax_class_id']) . '&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($Qreview-&gt;valueInt('products_id'))) ) {
+    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qreview-&gt;value('products_price'), $Qreview-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $Qreview-&gt;valueInt('products_tax_class_id')) . '&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_price = $osC_Currencies-&gt;displayPrice($review['products_price'], $review['products_tax_class_id']);
</pre><pre class="diff" id="added">+    $products_price = $osC_Currencies-&gt;displayPrice($Qreview-&gt;value('products_price'), $Qreview-&gt;valueInt('products_tax_class_id'));
</pre><pre class="diff" id="context">   }
 
</pre><pre class="diff" id="removed">-  if (tep_not_null($review['products_model'])) {
-    $products_name = $review['products_name'] . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $review['products_model'] . ']&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if (tep_not_null($Qreview-&gt;value('products_model'))) {
+    $products_name = $Qreview-&gt;value('products_name') . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $Qreview-&gt;value('products_model') . ']&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_name = $review['products_name'];
</pre><pre class="diff" id="added">+    $products_name = $Qreview-&gt;value('products_name');
</pre><pre class="diff" id="context">   }
 
   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PRODUCT_REVIEWS_INFO);
</pre><pre class="diff"><small id="info">@@ -94,8 +107,8 @@
</small></pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main"&gt;&lt;?php echo '&lt;b&gt;' . sprintf(TEXT_REVIEW_BY, tep_output_string_protected($review['customers_name'])) . '&lt;/b&gt;'; ?&gt;&lt;/td&gt;
-                    &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($review['date_added'])); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main"&gt;&lt;?php echo '&lt;b&gt;' . sprintf(TEXT_REVIEW_BY, $Qreview-&gt;valueProtected('customers_name')) . '&lt;/b&gt;'; ?&gt;&lt;/td&gt;
+                    &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($Qreview-&gt;value('date_added'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -105,7 +118,7 @@
</small></pre><pre class="diff" id="context">                     &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                       &lt;tr&gt;
                         &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                        &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string(nl2br(tep_output_string_protected($review['reviews_text'])), 60, '-&lt;br&gt;') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $review['reviews_rating'] . '.gif', sprintf(TEXT_OF_5_STARS, $review['reviews_rating'])), sprintf(TEXT_OF_5_STARS, $review['reviews_rating'])) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                        &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string(nl2br($Qreview-&gt;valueProtected('reviews_text')), 60, '-&lt;br&gt;') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $Qreview-&gt;valueInt('reviews_rating') . '.gif', sprintf(TEXT_OF_5_STARS, $Qreview-&gt;valueInt('reviews_rating'))), sprintf(TEXT_OF_5_STARS, $Qreview-&gt;value('reviews_rating'))) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                         &lt;td width="10" align="right"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                       &lt;/tr&gt;
                     &lt;/table&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -145,13 +158,13 @@
</small></pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td align="center" class="smallText"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if (tep_not_null($review['products_image'])) {
</pre><pre class="diff" id="added">+  if (tep_not_null($Qreview-&gt;value('products_image'))) {
</pre><pre class="diff" id="context"> ?&gt;
 &lt;script language="javascript"&gt;&lt;!--
</pre><pre class="diff" id="removed">-document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $review['products_id']) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $review['products_image'], addslashes($review['products_name']), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="added">+document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $Qreview-&gt;valueInt('products_id')) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $Qreview-&gt;value('products_image'), addslashes($Qreview-&gt;value('products_name')), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="context"> //--&gt;&lt;/script&gt;
 &lt;noscript&gt;
</pre><pre class="diff" id="removed">-&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $review['products_image']) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $review['products_image'], $review['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="added">+&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $Qreview-&gt;value('products_image')) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $Qreview-&gt;value('products_image'), $Qreview-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="context"> &lt;/noscript&gt;
 &lt;?php
   }
</pre></div>
<hr /><a name="file14" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>product_reviews_write.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php?rev=1.61&amp;content-type=text/vnd.viewcvs-markup">1.61</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php.diff?r1=1.61&amp;r2=1.62">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/product_reviews_write.php?rev=1.62&amp;content-type=text/vnd.viewcvs-markup">1.62</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.61 -r1.62
--- product_reviews_write.php	2004/11/03 09:00:50	1.61
+++ product_reviews_write.php	2005/03/07 10:04:36	1.62
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -13,87 +13,81 @@
</small></pre><pre class="diff" id="context">   require('includes/application_top.php');
 
   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PRODUCT_REVIEWS_WRITE);
</pre><pre class="diff" id="removed">-  
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">   if (!$osC_Services-&gt;isStarted('reviews')) {
     tep_redirect(tep_href_link(FILENAME_DEFAULT));
   }
</pre><pre class="diff" id="removed">- 
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">   if ( ($osC_Customer-&gt;isLoggedOn() == false ) &amp;&amp; (SERVICE_REVIEW_ENABLE_REVIEWS == 1) ) {
     $navigation-&gt;set_snapshot();
 
     tep_redirect(tep_href_link(FILENAME_LOGIN, '', 'SSL'));
   }
</pre><pre class="diff" id="added">+
+  $Qproduct = $osC_Database-&gt;query('select p.products_id, p.products_model, p.products_image, p.products_price, p.products_tax_class_id, pd.products_name from :table_products p, :table_products_description pd where p.products_id = :products_id and p.products_status = 1 and p.products_id = pd.products_id and pd.language_id = :language_id');
+  $Qproduct-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qproduct-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qproduct-&gt;bindInt(':products_id', $_GET['products_id']);
+  $Qproduct-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qproduct-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  $product_info_query = tep_db_query("select p.products_id, p.products_model, p.products_image, p.products_price, p.products_tax_class_id, pd.products_name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_id = '" . (int)$_GET['products_id'] . "' and p.products_status = '1' and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-  if (!tep_db_num_rows($product_info_query)) {
</pre><pre class="diff" id="added">+  if ($Qproduct-&gt;numberOfRows() &lt; 1) {
</pre><pre class="diff" id="context">     tep_redirect(tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params(array('action'))));
</pre><pre class="diff" id="removed">-  } else {
-    $product_info = tep_db_fetch_array($product_info_query);
</pre><pre class="diff" id="context">   }
 
</pre><pre class="diff" id="removed">-  if ($osC_Customer-&gt;isLoggedOn() === true) {
-    $customer_query = tep_db_query("select customers_firstname, customers_lastname from " . TABLE_CUSTOMERS . " where customers_id = '" . (int)$osC_Customer-&gt;id . "'");
-    $customer = tep_db_fetch_array($customer_query);
-  }
-  
</pre><pre class="diff" id="context">   if (isset($_GET['action']) &amp;&amp; ($_GET['action'] == 'process')) {
</pre><pre class="diff" id="removed">-    $rating = tep_db_prepare_input($_POST['rating']);
-    $review = tep_db_prepare_input($_POST['review']);
</pre><pre class="diff" id="added">+    if ($osC_Customer-&gt;isLoggedOn() === false) {
+      $customer_name = $_POST['customer_name'];
+    } else {
+      $customer_name = $osC_Customer-&gt;first_name . ' ' . $osC_Customer-&gt;last_name;
+    }
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if ($osC_Customer-&gt;isLoggedOn() === false) {
-  	 $customer_name = $_POST['customer_name'];
-  } else {
-  	 $customer_name = $customer['customers_firstname'] . ' ' . $customer['customers_lastname'];  	
-  }
-  
-    
</pre><pre class="diff" id="context">     $error = false;
</pre><pre class="diff" id="removed">-    if (strlen(<span id="removedchars">$review</span>) &lt; REVIEW_TEXT_MIN_LENGTH) {
</pre><pre class="diff" id="added">+    if (strlen(<span id="addedchars">trim($_POST['review'])</span>) &lt; REVIEW_TEXT_MIN_LENGTH) {
</pre><pre class="diff" id="context">       $error = true;
 
       $messageStack-&gt;add('review', JS_REVIEW_TEXT);
     }
 
</pre><pre class="diff" id="removed">-    if (($rating &lt; 1) || ($rating &gt; 5)) {
</pre><pre class="diff" id="added">+    if (($_POST['rating'] &lt; 1) || ($_POST['rating'] &gt; 5)) {
</pre><pre class="diff" id="context">       $error = true;
 
       $messageStack-&gt;add('review', JS_REVIEW_RATING);
     }
</pre><pre class="diff" id="removed">-
-    if ($error == false) {
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-    	if ($osC_Reviews-&gt;is_moderated === true) {
</pre><pre class="diff" id="added">+    if ($error === false) {
+      if ($osC_Reviews-&gt;is_moderated === true) {
</pre><pre class="diff" id="context">         $reviews_status = '0';
         $messageStack-&gt;add_session('reviews', TEXT_REVIEW_MODERATION, 'success');
</pre><pre class="diff" id="removed">-    	} else {
-        $reviews_status = '1';    		
-    	}
-    	
</pre><pre class="diff" id="added">+      } else {
+        $reviews_status = '1';
+      }
+
</pre><pre class="diff" id="context">       $Qreview = $osC_Database-&gt;query('insert into :table_reviews (products_id, customers_id, customers_name, reviews_rating, languages_id, reviews_text, reviews_status, date_added) values (:products_id, :customer_id, :customers_name, :rating, :language_id, :review, :review_status, now())');
       $Qreview-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
       $Qreview-&gt;bindInt(':products_id', $_GET['products_id']);
       $Qreview-&gt;bindInt(':customer_id', $osC_Customer-&gt;id);
       $Qreview-&gt;bindValue(':customers_name', $customer_name);
</pre><pre class="diff" id="removed">-      $Qreview-&gt;bindValue(':rating', <span id="removedchars">trim($rating)</span>);
</pre><pre class="diff" id="added">+      $Qreview-&gt;bindValue(':rating', <span id="addedchars">$_POST['rating']</span>);
</pre><pre class="diff" id="context">       $Qreview-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
</pre><pre class="diff" id="removed">-      $Qreview-&gt;bindValue(':review', <span id="removedchars">trim($review)</span>);
</pre><pre class="diff" id="added">+      $Qreview-&gt;bindValue(':review', <span id="addedchars">$_POST['review']</span>);
</pre><pre class="diff" id="context">       $Qreview-&gt;bindInt(':review_status', $reviews_status);
       $Qreview-&gt;execute();
</pre><pre class="diff" id="removed">- 
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">       tep_redirect(tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params(array('action'))));
     }
   }
 
</pre><pre class="diff" id="removed">-  if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($product_info['products_id'])) ) {
-    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $product_info['products_tax_class_id']) . '&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if ($osC_Services-&gt;isStarted('specials') &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($Qproduct-&gt;valueInt('products_id')))) {
+    $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qproduct-&gt;value('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $Qproduct-&gt;valueInt('products_tax_class_id')) . '&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_price = $osC_Currencies-&gt;displayPrice($product_info['products_price'], $product_info['products_tax_class_id']);
</pre><pre class="diff" id="added">+    $products_price = $osC_Currencies-&gt;displayPrice($Qproduct-&gt;valueInt('products_price'), $Qproduct-&gt;valueInt('products_tax_class_id'));
</pre><pre class="diff" id="context">   }
 
</pre><pre class="diff" id="removed">-  if (tep_not_null($product_info['products_model'])) {
-    $products_name = $product_info['products_name'] . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $product_info['products_model'] . ']&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if (tep_not_null($Qproduct-&gt;value('products_model'))) {
+    $products_name = $Qproduct-&gt;value('products_name') . '&lt;br&gt;&lt;span class="smallText"&gt;[' . $Qproduct-&gt;value('products_model') . ']&lt;/span&gt;';
</pre><pre class="diff" id="context">   } else {
</pre><pre class="diff" id="removed">-    $products_name = $product_info['products_name'];
</pre><pre class="diff" id="added">+    $products_name = $Qproduct-&gt;value('products_name');
</pre><pre class="diff" id="context">   }
 
   $breadcrumb-&gt;add(NAVBAR_TITLE, tep_href_link(FILENAME_PRODUCT_REVIEWS, tep_get_all_get_params()));
</pre><pre class="diff"><small id="info">@@ -180,7 +174,7 @@
</small></pre><pre class="diff" id="context">             &lt;td valign="top"&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
   if ($osC_Customer-&gt;isLoggedOn() == false) {
</pre><pre class="diff" id="removed">-?&gt;  
</pre><pre class="diff" id="added">+?&gt;
</pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td&gt;&lt;table width="50%" border="0" cellspacing="0" cellpadding="2"&gt;
                 &lt;tr&gt;
</pre><pre class="diff"><small id="info">@@ -202,13 +196,13 @@
</small></pre><pre class="diff" id="context">             &lt;/tr&gt;
 &lt;?php
   } else {
</pre><pre class="diff" id="removed">- ?&gt;<span id="removedchars">&nbsp;</span>
</pre><pre class="diff" id="added">+ ?&gt;
</pre><pre class="diff" id="context">               &lt;tr&gt;
</pre><pre class="diff" id="removed">-                &lt;td class="main"&gt;&lt;?php echo '&lt;b&gt;' . SUB_TITLE_FROM . '&lt;/b&gt; ' . tep_output_string_protected($customer['customers_firstname'] . ' ' . $customer['customers_lastname']); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                &lt;td class="main"&gt;&lt;?php echo '&lt;b&gt;' . SUB_TITLE_FROM . '&lt;/b&gt; ' . tep_output_string_protected($osC_Customer-&gt;first_name . ' ' . $osC_Customer-&gt;last_name); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">               &lt;/tr&gt;
 &lt;?php
   }
</pre><pre class="diff" id="removed">- ?&gt;         
</pre><pre class="diff" id="added">+ ?&gt;
</pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td class="main"&gt;&lt;b&gt;&lt;?php echo SUB_TITLE_REVIEW; ?&gt;&lt;/b&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -251,18 +245,18 @@
</small></pre><pre class="diff" id="context">               &lt;tr&gt;
                 &lt;td align="center" class="smallText"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if (tep_not_null($product_info['products_image'])) {
</pre><pre class="diff" id="added">+  if (tep_not_null($Qproduct-&gt;value('products_image'))) {
</pre><pre class="diff" id="context"> ?&gt;
 &lt;script language="javascript"&gt;&lt;!--
</pre><pre class="diff" id="removed">-document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $product_info['products_id']) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], addslashes($product_info['products_name']), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="added">+document.write('&lt;?php echo '&lt;a href="javascript:popupWindow(\\\'' . tep_href_link(FILENAME_POPUP_IMAGE, 'pID=' . $Qproduct-&gt;valueInt('products_id')) . '\\\')"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), addslashes($Qproduct-&gt;value('products_name')), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;');
</pre><pre class="diff" id="context"> //--&gt;&lt;/script&gt;
 &lt;noscript&gt;
</pre><pre class="diff" id="removed">-&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $product_info['products_image']) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $product_info['products_image'], $product_info['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="added">+&lt;?php echo '&lt;a href="' . tep_href_link(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image')) . '" target="_blank"&gt;' . tep_image(DIR_WS_IMAGES . $Qproduct-&gt;value('products_image'), $Qproduct-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT, 'hspace="5" vspace="5"') . '&lt;br&gt;' . TEXT_CLICK_TO_ENLARGE . '&lt;/a&gt;'; ?&gt;
</pre><pre class="diff" id="context"> &lt;/noscript&gt;
 &lt;?php
   }
 
</pre><pre class="diff" id="removed">-  echo '&lt;p&gt;&lt;a href="' . tep_href_link(<span id="removedchars">basename($_SERVER['PHP_SELF'])</span>, tep_get_all_get_params(array('action')) . 'action=buy_now') . '"&gt;' . tep_image_button('button_in_cart.gif', IMAGE_BUTTON_IN_CART) . '&lt;/a&gt;&lt;/p&gt;';
</pre><pre class="diff" id="added">+  echo '&lt;p&gt;&lt;a href="' . tep_href_link(<span id="addedchars">FILENAME_PRODUCT_REVIEWS_WRITE</span>, tep_get_all_get_params(array('action')) . 'action=buy_now') . '"&gt;' . tep_image_button('button_in_cart.gif', IMAGE_BUTTON_IN_CART) . '&lt;/a&gt;&lt;/p&gt;';
</pre><pre class="diff" id="context"> ?&gt;
                 &lt;/td&gt;
               &lt;/tr&gt;
</pre></div>
<hr /><a name="file15" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>products_new.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php?rev=1.31&amp;content-type=text/vnd.viewcvs-markup">1.31</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php.diff?r1=1.31&amp;r2=1.32">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/products_new.php?rev=1.32&amp;content-type=text/vnd.viewcvs-markup">1.32</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.31 -r1.32
--- products_new.php	2004/10/31 09:46:09	1.31
+++ products_new.php	2005/03/07 10:04:36	1.32
@@ -5,13 +5,17 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
 
   require('includes/application_top.php');
 
</pre><pre class="diff" id="added">+  if (!isset($_GET['page']) || (isset($_GET['page']) &amp;&amp; !is_numeric($_GET['page']))) {
+    $_GET['page'] = 1;
+  }
+
</pre><pre class="diff" id="context">   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_PRODUCTS_NEW);
 
   $breadcrumb-&gt;add(NAVBAR_TITLE, tep_href_link(FILENAME_PRODUCTS_NEW));
</pre><pre class="diff"><small id="info">@@ -51,18 +55,21 @@
</small></pre><pre class="diff" id="context">         &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
       &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  $products_new_array = array();
-
-  $products_new_query_raw = "select p.products_id, pd.products_name, p.products_image, p.products_price, p.products_tax_class_id, p.products_date_added, m.manufacturers_name from " . TABLE_PRODUCTS . " p left join " . TABLE_MANUFACTURERS . " m on (p.manufacturers_id = m.manufacturers_id), " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_status = '1' and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' order by p.products_date_added DESC, pd.products_name";
-  $products_new_split = new splitPageResults($products_new_query_raw, MAX_DISPLAY_PRODUCTS_NEW);
</pre><pre class="diff" id="added">+  $Qproducts = $osC_Database-&gt;query('select p.products_id, pd.products_name, p.products_image, p.products_price, p.products_tax_class_id, p.products_date_added, m.manufacturers_name from :table_products p left join :table_manufacturers m on (p.manufacturers_id = m.manufacturers_id), :table_products_description pd where p.products_status = 1 and p.products_id = pd.products_id and pd.language_id = :language_id order by p.products_date_added desc, pd.products_name');
+  $Qproducts-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qproducts-&gt;bindTable(':table_manufacturers', TABLE_MANUFACTURERS);
+  $Qproducts-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qproducts-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qproducts-&gt;setBatchLimit($_GET['page'], MAX_DISPLAY_PRODUCTS_NEW);
+  $Qproducts-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if (($products_new_split-&gt;number_of_rows &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+  if ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3')) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="smallText"&gt;&lt;?php echo $products_new_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_PRODUCTS_NEW); ?&gt;&lt;/td&gt;
-            &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $products_new_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info', 'x', 'y'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="smallText"&gt;&lt;?php echo $Qproducts-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_PRODUCTS_NEW); ?&gt;&lt;/td&gt;
+            &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qproducts-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -75,19 +82,18 @@
</small></pre><pre class="diff" id="context">       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if ($products_new_split-&gt;number_of_rows &gt; 0) {
-    $products_new_query = tep_db_query($products_new_split-&gt;sql_query);
-    while ($products_new = tep_db_fetch_array($products_new_query)) {
-      if ( ($osC_Services-&gt;isStarted('specials')) &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($products_new['products_id'])) ) {
-        $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($products_new['products_price'], $products_new['products_tax_class_id']) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $products_new['products_tax_class_id']) . '&lt;/span&gt;';
</pre><pre class="diff" id="added">+  if ($Qproducts-&gt;numberOfRows() &gt; 0) {
+    while ($Qproducts-&gt;next()) {
+      if ($osC_Services-&gt;isStarted('specials') &amp;&amp; ($new_price = $osC_Specials-&gt;getPrice($Qproducts-&gt;valueInt('products_id')))) {
+        $products_price = '&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qproducts-&gt;value('products_price'), $Qproducts-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt; &lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($new_price, $Qproducts-&gt;valueInt('products_tax_class_id')) . '&lt;/span&gt;';
</pre><pre class="diff" id="context">       } else {
</pre><pre class="diff" id="removed">-        $products_price = $osC_Currencies-&gt;displayPrice($products_new['products_price'], $products_new['products_tax_class_id']);
</pre><pre class="diff" id="added">+        $products_price = $osC_Currencies-&gt;displayPrice($Qproducts-&gt;value('products_price'), $Qproducts-&gt;valueInt('products_tax_class_id'));
</pre><pre class="diff" id="context">       }
 ?&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td width="&lt;?php echo SMALL_IMAGE_WIDTH + 10; ?&gt;" valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $products_new['products_id']) . '"&gt;' . tep_image(DIR_WS_IMAGES . $products_new['products_image'], $products_new['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
-            &lt;td valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $products_new['products_id']) . '"&gt;&lt;b&gt;&lt;u&gt;' . $products_new['products_name'] . '&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;br&gt;' . TEXT_DATE_ADDED . ' ' . tep_date_long($products_new['products_date_added']) . '&lt;br&gt;' . TEXT_MANUFACTURER . ' ' . $products_new['manufacturers_name'] . '&lt;br&gt;&lt;br&gt;' . TEXT_PRICE . ' ' . $products_price; ?&gt;&lt;/td&gt;
-            &lt;td align="right" valign="middle" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCTS_NEW, tep_get_all_get_params(array('action')) . 'action=buy_now&amp;products_id=' . $products_new['products_id']) . '"&gt;' . tep_image_button('button_in_cart.gif', IMAGE_BUTTON_IN_CART) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td width="&lt;?php echo SMALL_IMAGE_WIDTH + 10; ?&gt;" valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $Qproducts-&gt;valueInt('products_id')) . '"&gt;' . tep_image(DIR_WS_IMAGES . $Qproducts-&gt;value('products_image'), $Qproducts-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
+            &lt;td valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $Qproducts-&gt;valueInt('products_id')) . '"&gt;&lt;b&gt;&lt;u&gt;' . $Qproducts-&gt;value('products_name') . '&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;br&gt;' . TEXT_DATE_ADDED . ' ' . tep_date_long($Qproducts-&gt;value('products_date_added')) . '&lt;br&gt;' . TEXT_MANUFACTURER . ' ' . $Qproducts-&gt;value('manufacturers_name') . '&lt;br&gt;&lt;br&gt;' . TEXT_PRICE . ' ' . $products_price; ?&gt;&lt;/td&gt;
+            &lt;td align="right" valign="middle" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCTS_NEW, tep_get_all_get_params(array('action')) . 'action=buy_now&amp;products_id=' . $Qproducts-&gt;value('products_id')) . '"&gt;' . tep_image_button('button_in_cart.gif', IMAGE_BUTTON_IN_CART) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
           &lt;tr&gt;
             &lt;td colspan="3"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -108,13 +114,13 @@
</small></pre><pre class="diff" id="context">         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if (($products_new_split-&gt;number_of_rows &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+  if ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3')) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="smallText"&gt;&lt;?php echo $products_new_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_PRODUCTS_NEW); ?&gt;&lt;/td&gt;
-            &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $products_new_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info', 'x', 'y'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="smallText"&gt;&lt;?php echo $Qproducts-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_PRODUCTS_NEW); ?&gt;&lt;/td&gt;
+            &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qproducts-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre></div>
<hr /><a name="file16" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>redirect.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php?rev=1.13&amp;content-type=text/vnd.viewcvs-markup">1.13</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php.diff?r1=1.13&amp;r2=1.14">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/redirect.php?rev=1.14&amp;content-type=text/vnd.viewcvs-markup">1.14</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.13 -r1.14
--- redirect.php	2004/11/28 18:37:10	1.13
+++ redirect.php	2005/03/07 10:04:37	1.14
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -29,27 +29,37 @@
</small></pre><pre class="diff" id="context"> 
     case 'manufacturer':
       if (isset($_GET['manufacturers_id']) &amp;&amp; tep_not_null($_GET['manufacturers_id'])) {
</pre><pre class="diff" id="removed">-        $manufacturer_query = tep_db_query("select manufacturers_url from " . TABLE_MANUFACTURERS_INFO . " where manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "' and languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-        if (tep_db_num_rows($manufacturer_query)) {
-// url exists in selected language
-          $manufacturer = tep_db_fetch_array($manufacturer_query);
</pre><pre class="diff" id="added">+        $Qmanufacturer = $osC_Database-&gt;query('select manufacturers_url from :table_manufacturers_info where manufacturers_id = :manufacturers_id and languages_id = :languages_id');
+        $Qmanufacturer-&gt;bindTable(':table_manufacturers_info', TABLE_MANUFACTURERS_INFO);
+        $Qmanufacturer-&gt;bindInt(':manufacturers_id', $_GET['manufacturers_id']);
+        $Qmanufacturer-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+        $Qmanufacturer-&gt;execute();
+
+        if ($Qmanufacturer-&gt;numberOfRows() &amp;&amp; tep_not_null($Qmanufacturer-&gt;value('manufacturers_url'))) {
+          $Qupdate = $osC_Database-&gt;query('update :table_manufacturers_info set url_clicked = url_clicked+1, date_last_click = now() where manufacturers_id = :manufacturers_id and languages_id = :languages_id');
+          $Qupdate-&gt;bindTable(':table_manufacturers_info', TABLE_MANUFACTURERS_INFO);
+          $Qupdate-&gt;bindInt(':manufacturers_id', $_GET['manufacturers_id']);
+          $Qupdate-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+          $Qupdate-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-          if (tep_not_null($manufacturer['manufacturers_url'])) {
-            tep_db_query("update " . TABLE_MANUFACTURERS_INFO . " set url_clicked = url_clicked+1, date_last_click = now() where manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "' and languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-
-            tep_redirect($manufacturer['manufacturers_url']);
-          }
</pre><pre class="diff" id="added">+          tep_redirect($Qmanufacturer-&gt;value('manufacturers_url'));
</pre><pre class="diff" id="context">         } else {
 // no url exists for the selected language, lets use the default language then
</pre><pre class="diff" id="removed">-          $manufacturer_query = tep_db_query("select mi.languages_id, mi.manufacturers_url from " . TABLE_MANUFACTURERS_INFO . " mi, " . TABLE_LANGUAGES . " l where mi.manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "' and mi.languages_id = l.languages_id and l.code = '" . DEFAULT_LANGUAGE . "'");
-          if (tep_db_num_rows($manufacturer_query)) {
-            $manufacturer = tep_db_fetch_array($manufacturer_query);
-
-            if (tep_not_null($manufacturer['manufacturers_url'])) {
-              tep_db_query("update " . TABLE_MANUFACTURERS_INFO . " set url_clicked = url_clicked+1, date_last_click = now() where manufacturers_id = '" . (int)$_GET['manufacturers_id'] . "' and languages_id = '" . (int)$manufacturer['languages_id'] . "'");
</pre><pre class="diff" id="added">+          $Qmanufacturer = $osC_Database-&gt;query('select mi.languages_id, mi.manufacturers_url from :table_manufacturers_info mi, :table_languages l where mi.manufacturers_id = :manufacturers_id and mi.languages_id = l.languages_id and l.code = :code');
+          $Qmanufacturer-&gt;bindTable(':table_manufacturers_info', TABLE_MANUFACTURERS_INFO);
+          $Qmanufacturer-&gt;bindTable(':table_languages', TABLE_LANGUAGES);
+          $Qmanufacturer-&gt;bindInt(':manufacturers_id', $_GET['manufacturers_id']);
+          $Qmanufacturer-&gt;bindValue(':code', DEFAULT_LANGUAGE);
+          $Qmanufacturer-&gt;execute();
+
+          if ($Qmanufacturer-&gt;numberOfRows() &amp;&amp; tep_not_null($Qmanufacturer-&gt;value('manufacturers_url'))) {
+            $Qupdate = $osC_Database-&gt;query('update :table_manufacturers_info set url_clicked = url_clicked+1, date_last_click = now() where manufacturers_id = :manufacturers_id and languages_id = :languages_id');
+            $Qupdate-&gt;bindTable(':table_manufacturers_info', TABLE_MANUFACTURERS_INFO);
+            $Qupdate-&gt;bindInt(':manufacturers_id', $_GET['manufacturers_id']);
+            $Qupdate-&gt;bindInt(':languages_id', $Qmanufacturer-&gt;valueInt('languages_id'));
+            $Qupdate-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-              tep_redirect($manufacturer['manufacturers_url']);
-            }
</pre><pre class="diff" id="added">+            tep_redirect($Qmanufacturer-&gt;value('manufacturers_url'));
</pre><pre class="diff" id="context">           }
         }
       }
</pre></div>
<hr /><a name="file17" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>reviews.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php.diff?r1=1.53&amp;r2=1.54">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/reviews.php?rev=1.54&amp;content-type=text/vnd.viewcvs-markup">1.54</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.53 -r1.54
--- reviews.php	2004/11/03 09:00:50	1.53
+++ reviews.php	2005/03/07 10:04:37	1.54
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,7 +15,11 @@
</small></pre><pre class="diff" id="context">   if (!$osC_Services-&gt;isStarted('reviews')) {
     tep_redirect(tep_href_link(FILENAME_DEFAULT));
   }
</pre><pre class="diff" id="removed">-  
</pre><pre class="diff" id="added">+
+  if (!isset($_GET['page']) || (isset($_GET['page']) &amp;&amp; !is_numeric($_GET['page']))) {
+    $_GET['page'] = 1;
+  }
+
</pre><pre class="diff" id="context">   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_REVIEWS);
 
   $breadcrumb-&gt;add(NAVBAR_TITLE, tep_href_link(FILENAME_REVIEWS));
</pre><pre class="diff"><small id="info">@@ -57,17 +61,23 @@
</small></pre><pre class="diff" id="context">       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  $reviews_query_raw = "select r.reviews_id, left(r.reviews_text, 100) as reviews_text, r.reviews_rating, r.date_added, p.products_id, pd.products_name, p.products_image, r.customers_name from " . TABLE_REVIEWS . " r, " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_status = '1' and p.products_id = r.products_id and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and r.languages_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and r.reviews_status = 1 order by r.reviews_id DESC";
-  $reviews_split = new splitPageResults($reviews_query_raw, MAX_DISPLAY_NEW_REVIEWS);
</pre><pre class="diff" id="added">+  $Qreviews = $osC_Database-&gt;query('select r.reviews_id, left(r.reviews_text, 100) as reviews_text, r.reviews_rating, r.date_added, p.products_id, pd.products_name, p.products_image, r.customers_name from :table_reviews r, :table_products p, :table_products_description pd where p.products_status = 1 and p.products_id = r.products_id and p.products_id = pd.products_id and pd.language_id = :language_id and r.languages_id = :languages_id and r.reviews_status = 1 order by r.reviews_id desc');
+  $Qreviews-&gt;bindTable(':table_reviews', TABLE_REVIEWS);
+  $Qreviews-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qreviews-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qreviews-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qreviews-&gt;bindInt(':languages_id', $osC_Session-&gt;value('languages_id'));
+  $Qreviews-&gt;setBatchLimit($_GET['page'], MAX_DISPLAY_NEW_REVIEWS);
+  $Qreviews-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if ($reviews_split-&gt;number_of_rows &gt; 0) {
</pre><pre class="diff" id="added">+  if ($Qreviews-&gt;numberOfRows() &gt; 0) {
</pre><pre class="diff" id="context">     if ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3')) {
 ?&gt;
           &lt;tr&gt;
             &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
               &lt;tr&gt;
</pre><pre class="diff" id="removed">-                &lt;td class="smallText"&gt;&lt;?php echo $reviews_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
-                &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $reviews_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                &lt;td class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
+                &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">               &lt;/tr&gt;
             &lt;/table&gt;&lt;/td&gt;
           &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -77,14 +87,13 @@
</small></pre><pre class="diff" id="context"> &lt;?php
     }
 
</pre><pre class="diff" id="removed">-    $reviews_query = tep_db_query($reviews_split-&gt;sql_query);
-    while ($reviews = tep_db_fetch_array($reviews_query)) {
</pre><pre class="diff" id="added">+    while ($Qreviews-&gt;next()) {
</pre><pre class="diff" id="context"> ?&gt;
           &lt;tr&gt;
             &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
               &lt;tr&gt;
</pre><pre class="diff" id="removed">-                &lt;td class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $reviews['products_id'] . '&amp;reviews_id=' . $reviews['reviews_id']) . '"&gt;&lt;u&gt;&lt;b&gt;' . $reviews['products_name'] . '&lt;/b&gt;&lt;/u&gt;&lt;/a&gt; &lt;span class="smallText"&gt;' . sprintf(TEXT_REVIEW_BY, tep_output_string_protected($reviews['customers_name'])) . '&lt;/span&gt;'; ?&gt;&lt;/td&gt;
-                &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($reviews['date_added'])); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                &lt;td class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $Qreviews-&gt;valueInt('products_id') . '&amp;reviews_id=' . $Qreviews-&gt;valueInt('reviews_id')) . '"&gt;&lt;u&gt;&lt;b&gt;' . $Qreviews-&gt;value('products_name') . '&lt;/b&gt;&lt;/u&gt;&lt;/a&gt; &lt;span class="smallText"&gt;' . sprintf(TEXT_REVIEW_BY, $Qreviews-&gt;valueProtected('customers_name')) . '&lt;/span&gt;'; ?&gt;&lt;/td&gt;
+                &lt;td class="smallText" align="right"&gt;&lt;?php echo sprintf(TEXT_REVIEW_DATE_ADDED, tep_date_long($Qreviews-&gt;value('date_added'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">               &lt;/tr&gt;
             &lt;/table&gt;&lt;/td&gt;
           &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -94,8 +103,8 @@
</small></pre><pre class="diff" id="context">                 &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
                     &lt;td width="10"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                    &lt;td width="&lt;?php echo SMALL_IMAGE_WIDTH + 10; ?&gt;" align="center" valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $reviews['products_id'] . '&amp;reviews_id=' . $reviews['reviews_id']) . '"&gt;' . tep_image(DIR_WS_IMAGES . $reviews['products_image'], $reviews['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
-                    &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string(tep_output_string_protected($reviews['reviews_text']), 60, '-&lt;br&gt;') . ((strlen($reviews['reviews_text']) &gt;= 100) ? '..' : '') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $reviews['reviews_rating'] . '.gif', sprintf(TEXT_OF_5_STARS, $reviews['reviews_rating'])), sprintf(TEXT_OF_5_STARS, $reviews['reviews_rating'])) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td width="&lt;?php echo SMALL_IMAGE_WIDTH + 10; ?&gt;" align="center" valign="top" class="main"&gt;&lt;?php echo '&lt;a href="' . tep_href_link(FILENAME_PRODUCT_REVIEWS_INFO, 'products_id=' . $Qreviews-&gt;valueInt('products_id') . '&amp;reviews_id=' . $Qreviews-&gt;valueInt('reviews_id')) . '"&gt;' . tep_image(DIR_WS_IMAGES . $Qreviews-&gt;value('products_image'), $Qreviews-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;'; ?&gt;&lt;/td&gt;
+                    &lt;td valign="top" class="main"&gt;&lt;?php echo tep_break_string($Qreviews-&gt;valueProtected('reviews_text'), 60, '-&lt;br&gt;') . ((strlen($Qreviews-&gt;valueProtected('reviews_text')) &gt;= 100) ? '..' : '') . '&lt;br&gt;&lt;br&gt;&lt;i&gt;' . sprintf(TEXT_REVIEW_RATING, tep_image(DIR_WS_IMAGES . 'stars_' . $Qreviews-&gt;valueInt('reviews_rating') . '.gif', sprintf(TEXT_OF_5_STARS, $Qreviews-&gt;valueInt('reviews_rating'))), sprintf(TEXT_OF_5_STARS, $Qreviews-&gt;valueInt('reviews_rating'))) . '&lt;/i&gt;'; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                     &lt;td width="10" align="right"&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '10', '1'); ?&gt;&lt;/td&gt;
                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
</pre><pre class="diff"><small id="info">@@ -107,28 +116,26 @@
</small></pre><pre class="diff" id="context">           &lt;/tr&gt;
 &lt;?php
     }
</pre><pre class="diff" id="removed">-?&gt;
-&lt;?php
-  } else {
</pre><pre class="diff" id="added">+
+    if ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3')) {
</pre><pre class="diff" id="context"> ?&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td&gt;&lt;?php new infoBox(array(array('text' =&gt; TEXT_NO_REVIEWS))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
+              &lt;tr&gt;
+                &lt;td class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
+                &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qreviews-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
+              &lt;/tr&gt;
+            &lt;/table&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
           &lt;tr&gt;
             &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
           &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  }
-
-  if (($reviews_split-&gt;number_of_rows &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+    }
+  } else {
</pre><pre class="diff" id="context"> ?&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
-              &lt;tr&gt;
-                &lt;td class="smallText"&gt;&lt;?php echo $reviews_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_REVIEWS); ?&gt;&lt;/td&gt;
-                &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $reviews_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info'))); ?&gt;&lt;/td&gt;
-              &lt;/tr&gt;
-            &lt;/table&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td&gt;&lt;?php new infoBox(array(array('text' =&gt; TEXT_NO_REVIEWS))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
           &lt;tr&gt;
             &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
</pre></div>
<hr /><a name="file18" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>shopping_cart.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php?rev=1.76&amp;content-type=text/vnd.viewcvs-markup">1.76</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php.diff?r1=1.76&amp;r2=1.77">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/shopping_cart.php?rev=1.77&amp;content-type=text/vnd.viewcvs-markup">1.77</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.76 -r1.77
--- shopping_cart.php	2004/07/22 17:23:53	1.76
+++ shopping_cart.php	2005/03/07 10:04:37	1.77
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -79,22 +79,23 @@
</small></pre><pre class="diff" id="context">       if (isset($products[$i]['attributes']) &amp;&amp; is_array($products[$i]['attributes'])) {
         while (list($option, $value) = each($products[$i]['attributes'])) {
           echo osc_draw_hidden_field('id[' . $products[$i]['id'] . '][' . $option . ']', $value);
</pre><pre class="diff" id="removed">-          $attributes = tep_db_query("select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix
-                                      from " . TABLE_PRODUCTS_OPTIONS . " popt, " . TABLE_PRODUCTS_OPTIONS_VALUES . " poval, " . TABLE_PRODUCTS_ATTRIBUTES . " pa
-                                      where pa.products_id = '" . $products[$i]['id'] . "'
-                                       and pa.options_id = '" . $option . "'
-                                       and pa.options_id = popt.products_options_id
-                                       and pa.options_values_id = '" . $value . "'
-                                       and pa.options_values_id = poval.products_options_values_id
-                                       and popt.language_id = '" . $osC_Session-&gt;value('languages_id') . "'
-                                       and poval.language_id = '" . $osC_Session-&gt;value('languages_id') . "'");
-          $attributes_values = tep_db_fetch_array($attributes);
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-          $products[$i][$option]['products_options_name'] = $attributes_values['products_options_name'];
</pre><pre class="diff" id="added">+          $Qattributes = $osC_Database-&gt;query('select popt.products_options_name, poval.products_options_values_name, pa.options_values_price, pa.price_prefix from :table_products_options popt, :table_products_options_values poval, :table_products_attributes pa where pa.products_id = :products_id and pa.options_id = :options_id and pa.options_id = popt.products_options_id and pa.options_values_id = :options_values_id and pa.options_values_id = poval.products_options_values_id and popt.language_id = :language_id and poval.language_id = :language_id');
+          $Qattributes-&gt;bindTable(':table_products_options', TABLE_PRODUCTS_OPTIONS);
+          $Qattributes-&gt;bindTable(':table_products_options_values', TABLE_PRODUCTS_OPTIONS_VALUES);
+          $Qattributes-&gt;bindTable(':table_products_attributes', TABLE_PRODUCTS_ATTRIBUTES);
+          $Qattributes-&gt;bindInt(':products_id', $products[$i]['id']);
+          $Qattributes-&gt;bindInt(':options_id', $option);
+          $Qattributes-&gt;bindInt(':options_values_id', $value);
+          $Qattributes-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+          $Qattributes-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+          $Qattributes-&gt;execute();
+
+          $products[$i][$option]['products_options_name'] = $Qattributes-&gt;value('products_options_name');
</pre><pre class="diff" id="context">           $products[$i][$option]['options_values_id'] = $value;
</pre><pre class="diff" id="removed">-          $products[$i][$option]['products_options_values_name'] = $attributes_values['products_options_values_name'];
-          $products[$i][$option]['options_values_price'] = $attributes_values['options_values_price'];
-          $products[$i][$option]['price_prefix'] = $attributes_values['price_prefix'];
</pre><pre class="diff" id="added">+          $products[$i][$option]['products_options_values_name'] = $Qattributes-&gt;value('products_options_values_name');
+          $products[$i][$option]['options_values_price'] = $Qattributes-&gt;value('options_values_price');
+          $products[$i][$option]['price_prefix'] = $Qattributes-&gt;value('price_prefix');
</pre><pre class="diff" id="context">         }
       }
     }
</pre></div>
<hr /><a name="file19" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>specials.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php?rev=1.52&amp;content-type=text/vnd.viewcvs-markup">1.52</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php.diff?r1=1.52&amp;r2=1.53">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/specials.php?rev=1.53&amp;content-type=text/vnd.viewcvs-markup">1.53</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.52 -r1.53
--- specials.php	2004/10/31 09:46:09	1.52
+++ specials.php	2005/03/07 10:04:37	1.53
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">3</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -15,7 +15,11 @@
</small></pre><pre class="diff" id="context">   if (!$osC_Services-&gt;isStarted('specials')) {
     tep_redirect(tep_href_link(FILENAME_DEFAULT));
   }
</pre><pre class="diff" id="removed">-  
</pre><pre class="diff" id="added">+
+  if (!isset($_GET['page']) || (isset($_GET['page']) &amp;&amp; !is_numeric($_GET['page']))) {
+    $_GET['page'] = 1;
+  }
+
</pre><pre class="diff" id="context">   require(DIR_WS_LANGUAGES . $osC_Session-&gt;value('language') . '/' . FILENAME_SPECIALS);
 
   $breadcrumb-&gt;add(NAVBAR_TITLE, tep_href_link(FILENAME_SPECIALS));
</pre><pre class="diff"><small id="info">@@ -55,16 +59,21 @@
</small></pre><pre class="diff" id="context">         &lt;td&gt;&lt;?php echo tep_draw_separator('pixel_trans.gif', '100%', '10'); ?&gt;&lt;/td&gt;
       &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  $specials_query_raw = "select p.products_id, pd.products_name, p.products_price, p.products_tax_class_id, p.products_image, s.specials_new_products_price from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd, " . TABLE_SPECIALS . " s where p.products_status = '1' and s.products_id = p.products_id and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "' and s.status = '1' order by s.specials_date_added DESC";
-  $specials_split = new splitPageResults($specials_query_raw, MAX_DISPLAY_SPECIAL_PRODUCTS);
</pre><pre class="diff" id="added">+  $Qspecials = $osC_Database-&gt;query('select p.products_id, pd.products_name, p.products_price, p.products_tax_class_id, p.products_image, s.specials_new_products_price from :table_products p, :table_products_description pd, :table_specials s where p.products_status = 1 and s.products_id = p.products_id and p.products_id = pd.products_id and pd.language_id = :language_id and s.status = 1 order by s.specials_date_added desc');
+  $Qspecials-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+  $Qspecials-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+  $Qspecials-&gt;bindTable(':table_specials', TABLE_SPECIALS);
+  $Qspecials-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+  $Qspecials-&gt;setBatchLimit($_GET['page'], MAX_DISPLAY_SPECIAL_PRODUCTS);
+  $Qspecials-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-  if (($<span id="removedchars">specials_split-&gt;number_of_rows</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+  if (($<span id="addedchars">Qspecials-&gt;numberOfRows()</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '1') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="smallText"&gt;&lt;?php echo $specials_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_SPECIALS); ?&gt;&lt;/td&gt;
-            &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $specials_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info', 'x', 'y'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="smallText"&gt;&lt;?php echo $Qspecials-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_SPECIALS); ?&gt;&lt;/td&gt;
+            &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qspecials-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -79,11 +88,11 @@
</small></pre><pre class="diff" id="context">           &lt;tr&gt;
 &lt;?php
     $row = 0;
</pre><pre class="diff" id="removed">-    $specials_query = tep_db_query($specials_split-&gt;sql_query);
-    while ($specials = tep_db_fetch_array($specials_query)) {
</pre><pre class="diff" id="added">+
+    while ($Qspecials-&gt;next()) {
</pre><pre class="diff" id="context">       $row++;
 
</pre><pre class="diff" id="removed">-      echo '            &lt;td align="center" width="33%" class="smallText"&gt;&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $specials['products_id']) . '"&gt;' . tep_image(DIR_WS_IMAGES . $specials['products_image'], $specials['products_name'], SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;&lt;br&gt;&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $specials['products_id']) . '"&gt;' . $specials['products_name'] . '&lt;/a&gt;&lt;br&gt;&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($specials['products_price'], $specials['products_tax_class_id']) . '&lt;/s&gt;&lt;br&gt;&lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($specials['specials_new_products_price'], $specials['products_tax_class_id']) . '&lt;/span&gt;&lt;/td&gt;' . "\n";
</pre><pre class="diff" id="added">+      echo '            &lt;td align="center" width="33%" class="smallText"&gt;&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $Qspecials-&gt;valueInt('products_id')) . '"&gt;' . tep_image(DIR_WS_IMAGES . $Qspecials-&gt;value('products_image'), $Qspecials-&gt;value('products_name'), SMALL_IMAGE_WIDTH, SMALL_IMAGE_HEIGHT) . '&lt;/a&gt;&lt;br&gt;&lt;a href="' . tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $Qspecials-&gt;valueInt('products_id')) . '"&gt;' . $Qspecials-&gt;value('products_name') . '&lt;/a&gt;&lt;br&gt;&lt;s&gt;' . $osC_Currencies-&gt;displayPrice($Qspecials-&gt;value('products_price'), $Qspecials-&gt;valueInt('products_tax_class_id')) . '&lt;/s&gt;&lt;br&gt;&lt;span class="productSpecialPrice"&gt;' . $osC_Currencies-&gt;displayPrice($Qspecials-&gt;value('specials_new_products_price'), $Qspecials-&gt;valueInt(
 'products_tax_class_id')) . '&lt;/span&gt;&lt;/td&gt;' . "\n";
</pre><pre class="diff" id="context"> 
       if ((($row / 3) == floor($row / 3))) {
 ?&gt;
</pre><pre class="diff"><small id="info">@@ -100,13 +109,13 @@
</small></pre><pre class="diff" id="context">         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
 &lt;?php
</pre><pre class="diff" id="removed">-  if (($<span id="removedchars">specials_split-&gt;number_of_rows</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="added">+  if (($<span id="addedchars">Qspecials-&gt;numberOfRows()</span> &gt; 0) &amp;&amp; ((PREV_NEXT_BAR_LOCATION == '2') || (PREV_NEXT_BAR_LOCATION == '3'))) {
</pre><pre class="diff" id="context"> ?&gt;
       &lt;tr&gt;
         &lt;td&gt;&lt;br&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="2"&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="smallText"&gt;&lt;?php echo $specials_split-&gt;display_count(TEXT_DISPLAY_NUMBER_OF_SPECIALS); ?&gt;&lt;/td&gt;
-            &lt;td align="right" class="smallText"&gt;&lt;?php echo TEXT_RESULT_PAGE . ' ' . $specials_split-&gt;display_links(MAX_DISPLAY_PAGE_LINKS, tep_get_all_get_params(array('page', 'info', 'x', 'y'))); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="smallText"&gt;&lt;?php echo $Qspecials-&gt;displayBatchLinksTotal(TEXT_DISPLAY_NUMBER_OF_SPECIALS); ?&gt;&lt;/td&gt;
+            &lt;td align="right" class="smallText"&gt;&lt;?php echo $Qspecials-&gt;displayBatchLinksPullDown(); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre></div>
<hr /><a name="file20" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a><br /></span>
<div class="fileheader"><big><b>tell_a_friend.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php?rev=1.44&amp;content-type=text/vnd.viewcvs-markup">1.44</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php.diff?r1=1.44&amp;r2=1.45">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/tell_a_friend.php?rev=1.45&amp;content-type=text/vnd.viewcvs-markup">1.45</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.44 -r1.45
--- tell_a_friend.php	2004/07/22 17:23:53	1.44
+++ tell_a_friend.php	2005/03/07 10:04:37	1.45
@@ -5,7 +5,7 @@
</small></pre><pre class="diff" id="context">   osCommerce, Open Source E-Commerce Solutions
   http://www.oscommerce.com
 
</pre><pre class="diff" id="removed">-  Copyright (c) 200<span id="removedchars">4</span> osCommerce
</pre><pre class="diff" id="added">+  Copyright (c) 200<span id="addedchars">5</span> osCommerce
</pre><pre class="diff" id="context"> 
   Released under the GNU General Public License
 */
</pre><pre class="diff"><small id="info">@@ -19,12 +19,17 @@
</small></pre><pre class="diff" id="context">   }
 
   $valid_product = false;
</pre><pre class="diff" id="added">+
</pre><pre class="diff" id="context">   if (isset($_GET['products_id'])) {
</pre><pre class="diff" id="removed">-    $product_info_query = tep_db_query("select pd.products_name from " . TABLE_PRODUCTS . " p, " . TABLE_PRODUCTS_DESCRIPTION . " pd where p.products_status = '1' and p.products_id = '" . (int)$_GET['products_id'] . "' and p.products_id = pd.products_id and pd.language_id = '" . (int)$osC_Session-&gt;value('languages_id') . "'");
-    if (tep_db_num_rows($product_info_query)) {
-      $valid_product = true;
</pre><pre class="diff" id="added">+    $Qproduct = $osC_Database-&gt;query('select pd.products_name from :table_products p, :table_products_description pd where p.products_status = 1 and p.products_id = :products_id and p.products_id = pd.products_id and pd.language_id = :language_id');
+    $Qproduct-&gt;bindTable(':table_products', TABLE_PRODUCTS);
+    $Qproduct-&gt;bindTable(':table_products_description', TABLE_PRODUCTS_DESCRIPTION);
+    $Qproduct-&gt;bindInt(':products_id', $_GET['products_id']);
+    $Qproduct-&gt;bindInt(':language_id', $osC_Session-&gt;value('languages_id'));
+    $Qproduct-&gt;execute();
</pre><pre class="diff" id="context"> 
</pre><pre class="diff" id="removed">-      $product_info = tep_db_fetch_array($product_info_query);
</pre><pre class="diff" id="added">+    if ($Qproduct-&gt;numberOfRows()) {
+      $valid_product = true;
</pre><pre class="diff" id="context">     }
   }
 
</pre><pre class="diff"><small id="info">@@ -37,11 +42,11 @@
</small></pre><pre class="diff" id="context">   if (isset($_GET['action']) &amp;&amp; ($_GET['action'] == 'process')) {
     $error = false;
 
</pre><pre class="diff" id="removed">-    $to_email_address = tep_db_prepare_input($_POST['to_email_address']);
-    $to_name = tep_db_prepare_input($_POST['to_name']);
-    $from_email_address = tep_db_prepare_input($_POST['from_email_address']);
-    $from_name = tep_db_prepare_input($_POST['from_name']);
-    $message = tep_db_prepare_input($_POST['message']);
</pre><pre class="diff" id="added">+    $to_email_address = tep_sanitize_string($_POST['to_email_address']);
+    $to_name = tep_sanitize_string($_POST['to_name']);
+    $from_email_address = tep_sanitize_string($_POST['from_email_address']);
+    $from_name = tep_sanitize_string($_POST['from_name']);
+    $message = tep_sanitize_string($_POST['message']);
</pre><pre class="diff" id="context"> 
     if (empty($from_name)) {
       $error = true;
</pre><pre class="diff"><small id="info">@@ -69,7 +74,7 @@
</small></pre><pre class="diff" id="context"> 
     if ($error == false) {
       $email_subject = sprintf(TEXT_EMAIL_SUBJECT, $from_name, STORE_NAME);
</pre><pre class="diff" id="removed">-      $email_body = sprintf(TEXT_EMAIL_INTRO, $to_name, $from_name, $<span id="removedchars">product_info['products_name']</span>, STORE_NAME) . "\n\n";
</pre><pre class="diff" id="added">+      $email_body = sprintf(TEXT_EMAIL_INTRO, $to_name, $from_name, $<span id="addedchars">Qproduct-&gt;value('products_name')</span>, STORE_NAME) . "\n\n";
</pre><pre class="diff" id="context"> 
       if (tep_not_null($message)) {
         $email_body .= $message . "\n\n";
</pre><pre class="diff"><small id="info">@@ -80,16 +85,13 @@
</small></pre><pre class="diff" id="context"> 
       tep_mail($to_name, $to_email_address, $email_subject, $email_body, $from_name, $from_email_address);
 
</pre><pre class="diff" id="removed">-      $messageStack-&gt;add_session('header', sprintf(TEXT_EMAIL_SUCCESSFUL_SENT, $<span id="removedchars">product_info['products_name']</span>, tep_output_string_protected($to_name)), 'success');
</pre><pre class="diff" id="added">+      $messageStack-&gt;add_session('header', sprintf(TEXT_EMAIL_SUCCESSFUL_SENT, $<span id="addedchars">Qproduct-&gt;value('products_name')</span>, tep_output_string_protected($to_name)), 'success');
</pre><pre class="diff" id="context"> 
       tep_redirect(tep_href_link(FILENAME_PRODUCT_INFO, 'products_id=' . $_GET['products_id']));
     }
   } elseif ($osC_Customer-&gt;isLoggedOn()) {
</pre><pre class="diff" id="removed">-    $account_query = tep_db_query("select customers_firstname, customers_lastname, customers_email_address from " . TABLE_CUSTOMERS . " where customers_id = '" . (int)$osC_Customer-&gt;id . "'");
-    $account = tep_db_fetch_array($account_query);
-
-    $from_name = $account['customers_firstname'] . ' ' . $account['customers_lastname'];
-    $from_email_address = $account['customers_email_address'];
</pre><pre class="diff" id="added">+    $from_name = $osC_Customer-&gt;first_name . ' ' . $osC_Customer-&gt;last_name;
+    $from_email_address = $osC_Customer-&gt;email_address;
</pre><pre class="diff" id="context">   }
 
   $breadcrumb-&gt;add(NAVBAR_TITLE, tep_href_link(FILENAME_TELL_A_FRIEND, 'products_id=' . $_GET['products_id']));
</pre><pre class="diff"><small id="info">@@ -120,8 +122,8 @@
</small></pre><pre class="diff" id="context">       &lt;tr&gt;
         &lt;td&gt;&lt;table border="0" width="100%" cellspacing="0" cellpadding="0"&gt;
           &lt;tr&gt;
</pre><pre class="diff" id="removed">-            &lt;td class="pageHeading"&gt;&lt;?php echo sprintf(HEADING_TITLE, $product_info['products_name']); ?&gt;&lt;/td&gt;
-            &lt;td class="pageHeading" align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . 'table_background_contact_us.gif', sprintf(HEADING_TITLE, $product_info['products_name']), HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+            &lt;td class="pageHeading"&gt;&lt;?php echo sprintf(HEADING_TITLE, $Qproduct-&gt;value('products_name')); ?&gt;&lt;/td&gt;
+            &lt;td class="pageHeading" align="right"&gt;&lt;?php echo tep_image(DIR_WS_IMAGES . 'table_background_contact_us.gif', sprintf(HEADING_TITLE, $Qproduct-&gt;value('products_name')), HEADING_IMAGE_WIDTH, HEADING_IMAGE_HEIGHT); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">           &lt;/tr&gt;
         &lt;/table&gt;&lt;/td&gt;
       &lt;/tr&gt;
</pre><pre class="diff"><small id="info">@@ -156,11 +158,11 @@
</small></pre><pre class="diff" id="context">                 &lt;td&gt;&lt;table border="0" cellspacing="0" cellpadding="2"&gt;
                   &lt;tr&gt;
                     &lt;td class="main"&gt;&lt;?php echo FORM_FIELD_CUSTOMER_NAME; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main"&gt;&lt;?php echo osc_draw_input_field('from_name', <span id="removedchars">''</span>, '', true); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main"&gt;&lt;?php echo osc_draw_input_field('from_name', <span id="addedchars">$from_name</span>, '', true); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                   &lt;tr&gt;
                     &lt;td class="main"&gt;&lt;?php echo FORM_FIELD_CUSTOMER_EMAIL; ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="removed">-                    &lt;td class="main"&gt;&lt;?php echo osc_draw_input_field('from_email_address', <span id="removedchars">''</span>, '', true); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="added">+                    &lt;td class="main"&gt;&lt;?php echo osc_draw_input_field('from_email_address', <span id="addedchars">$from_email_address</span>, '', true); ?&gt;&lt;/td&gt;
</pre><pre class="diff" id="context">                   &lt;/tr&gt;
                 &lt;/table&gt;&lt;/td&gt;
               &lt;/tr&gt;
</pre></div>
<hr /><a name="file21" /><div class="file">
<span class="pathname"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes">includes</a><br /></span>
<div class="fileheader"><big><b>application_top.php</b></big> <small id="info"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php?rev=1.289&amp;content-type=text/vnd.viewcvs-markup">1.289</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php.diff?r1=1.289&amp;r2=1.290">-&gt;</a> <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/application_top.php?rev=1.290&amp;content-type=text/vnd.viewcvs-markup">1.290</a></small></div>
<pre class="diff"><small id="info">diff -u -r1.289 -r1.290
--- application_top.php	2005/02/23 16:08:29	1.289
+++ application_top.php	2005/03/07 10:04:39	1.290
@@ -61,9 +61,6 @@
</small></pre><pre class="diff" id="context">   require('includes/classes/cache.php');
   $osC_Cache = new osC_Cache;
 
</pre><pre class="diff" id="removed">-// include the database functions
-  require('includes/functions/database.php');
-
</pre><pre class="diff" id="context"> // include the database class
   require('includes/classes/database.php');
 
</pre><pre class="diff"><small id="info">@@ -237,9 +234,6 @@
</small></pre><pre class="diff" id="context"> // include the mail classes
   require('includes/classes/mime.php');
   require('includes/classes/email.php');
</pre><pre class="diff" id="removed">-
-// split-page-results
-  require('includes/classes/split_page_results.php');
</pre><pre class="diff" id="context"> 
 // infobox
   require('includes/classes/boxes.php');
</pre></div>
<hr /><a name="file22" /><div class="file">
<span class="pathname" id="removed"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes">includes</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/classes">classes</a><br /></span>
<div class="fileheader" id="removed"><big><b>split_page_results.php</b></big> <small id="info">removed after <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/classes/split_page_results.php?rev=1.17&amp;content-type=text/vnd.viewcvs-markup">1.17</a></small></div>
<pre class="diff"><small id="info">diff -N split_page_results.php
--- /tmp/cvsAAAZsaie2	Mon Mar  7 11:04:40 2005
+++ /dev/null	Mon Mar  7 11:04:40 2005
@@ -1,135 +0,0 @@
</small></pre><pre class="diff" id="removed">-&lt;?php
-/*
-  $Id$
-
-  osCommerce, Open Source E-Commerce Solutions
-  http://www.oscommerce.com
-
-  Copyright (c) 2003 osCommerce
-
-  Released under the GNU General Public License
-*/
-
-  class splitPageResults {
-    var $sql_query, $number_of_rows, $current_page_number, $number_of_pages, $number_of_rows_per_page, $page_name;
-
-/* class constructor */
-    function splitPageResults($query, $max_rows, $count_key = '*', $page_holder = 'page') {
-      if (PHP_VERSION &lt; 4.1) {
-        global $_GET, $_POST;
-      }
-
-      $this-&gt;sql_query = $query;
-      $this-&gt;page_name = $page_holder;
-
-      if (isset($_GET[$page_holder])) {
-        $page = $_GET[$page_holder];
-      } elseif (isset($_POST[$page_holder])) {
-        $page = $_POST[$page_holder];
-      } else {
-        $page = '';
-      }
-
-      if (empty($page) || !is_numeric($page)) $page = 1;
-      $this-&gt;current_page_number = $page;
-
-      $this-&gt;number_of_rows_per_page = $max_rows;
-
-      $pos_to = strlen($this-&gt;sql_query);
-      $pos_from = strpos($this-&gt;sql_query, ' from', 0);
-
-      $pos_group_by = strpos($this-&gt;sql_query, ' group by', $pos_from);
-      if (($pos_group_by &lt; $pos_to) &amp;&amp; ($pos_group_by != false)) $pos_to = $pos_group_by;
-
-      $pos_having = strpos($this-&gt;sql_query, ' having', $pos_from);
-      if (($pos_having &lt; $pos_to) &amp;&amp; ($pos_having != false)) $pos_to = $pos_having;
-
-      $pos_order_by = strpos($this-&gt;sql_query, ' order by', $pos_from);
-      if (($pos_order_by &lt; $pos_to) &amp;&amp; ($pos_order_by != false)) $pos_to = $pos_order_by;
-
-      if (strpos($this-&gt;sql_query, 'distinct') || strpos($this-&gt;sql_query, 'group by')) {
-        $count_string = 'distinct ' . tep_db_input($count_key);
-      } else {
-        $count_string = tep_db_input($count_key);
-      }
-
-      $count_query = tep_db_query("select count(" . $count_string . ") as total " . substr($this-&gt;sql_query, $pos_from, ($pos_to - $pos_from)));
-      $count = tep_db_fetch_array($count_query);
-
-      $this-&gt;number_of_rows = $count['total'];
-
-      $this-&gt;number_of_pages = ceil($this-&gt;number_of_rows / $this-&gt;number_of_rows_per_page);
-
-      if ($this-&gt;current_page_number &gt; $this-&gt;number_of_pages) {
-        $this-&gt;current_page_number = $this-&gt;number_of_pages;
-      }
-
-      $offset = ($this-&gt;number_of_rows_per_page * ($this-&gt;current_page_number - 1));
-
-      $this-&gt;sql_query .= " limit " . $offset . ", " . $this-&gt;number_of_rows_per_page;
-    }
-
-/* class functions */
-
-// display split-page-number-links
-    function display_links($max_page_links, $parameters = '') {
-      if (PHP_VERSION &lt; 4.1) {
-        global $_SERVER;
-      }
-
-      global $request_type;
-
-      $display_links_string = '';
-
-      $class = 'class="pageResults"';
-
-      if (tep_not_null($parameters) &amp;&amp; (substr($parameters, -1) != '&amp;')) $parameters .= '&amp;';
-
-// previous button - not displayed on first page
-      if ($this-&gt;current_page_number &gt; 1) $display_links_string .= '&lt;a href="' . tep_href_link(basename($_SERVER['PHP_SELF']), $parameters . $this-&gt;page_name . '=' . ($this-&gt;current_page_number - 1), $request_type) . '" class="pageResults" title=" ' . PREVNEXT_TITLE_PREVIOUS_PAGE . ' "&gt;&lt;u&gt;' . PREVNEXT_BUTTON_PREV . '&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;';
-
-// check if number_of_pages &gt; $max_page_links
-      $cur_window_num = intval($this-&gt;current_page_number / $max_page_links);
-      if ($this-&gt;current_page_number % $max_page_links) $cur_window_num++;
-
-      $max_window_num = intval($this-&gt;number_of_pages / $max_page_links);
-      if ($this-&gt;number_of_pages % $max_page_links) $max_window_num++;
-
-// previous window of pages
-      if ($cur_window_num &gt; 1) $display_links_string .= '&lt;a href="' . tep_href_link(basename($_SERVER['PHP_SELF']), $parameters . $this-&gt;page_name . '=' . (($cur_window_num - 1) * $max_page_links), $request_type) . '" class="pageResults" title=" ' . sprintf(PREVNEXT_TITLE_PREV_SET_OF_NO_PAGE, $max_page_links) . ' "&gt;...&lt;/a&gt;';
-
-// page nn button
-      for ($jump_to_page = 1 + (($cur_window_num - 1) * $max_page_links); ($jump_to_page &lt;= ($cur_window_num * $max_page_links)) &amp;&amp; ($jump_to_page &lt;= $this-&gt;number_of_pages); $jump_to_page++) {
-        if ($jump_to_page == $this-&gt;current_page_number) {
-          $display_links_string .= '&amp;nbsp;&lt;b&gt;' . $jump_to_page . '&lt;/b&gt;&amp;nbsp;';
-        } else {
-          $display_links_string .= '&amp;nbsp;&lt;a href="' . tep_href_link(basename($_SERVER['PHP_SELF']), $parameters . $this-&gt;page_name . '=' . $jump_to_page, $request_type) . '" class="pageResults" title=" ' . sprintf(PREVNEXT_TITLE_PAGE_NO, $jump_to_page) . ' "&gt;&lt;u&gt;' . $jump_to_page . '&lt;/u&gt;&lt;/a&gt;&amp;nbsp;';
-        }
-      }
-
-// next window of pages
-      if ($cur_window_num &lt; $max_window_num) $display_links_string .= '&lt;a href="' . tep_href_link(basename($_SERVER['PHP_SELF']), $parameters . $this-&gt;page_name . '=' . (($cur_window_num) * $max_page_links + 1), $request_type) . '" class="pageResults" title=" ' . sprintf(PREVNEXT_TITLE_NEXT_SET_OF_NO_PAGE, $max_page_links) . ' "&gt;...&lt;/a&gt;&amp;nbsp;';
-
-// next button
-      if (($this-&gt;current_page_number &lt; $this-&gt;number_of_pages) &amp;&amp; ($this-&gt;number_of_pages != 1)) $display_links_string .= '&amp;nbsp;&lt;a href="' . tep_href_link(basename($_SERVER['PHP_SELF']), $parameters . 'page=' . ($this-&gt;current_page_number + 1), $request_type) . '" class="pageResults" title=" ' . PREVNEXT_TITLE_NEXT_PAGE . ' "&gt;&lt;u&gt;' . PREVNEXT_BUTTON_NEXT . '&lt;/u&gt;&lt;/a&gt;&amp;nbsp;';
-
-      return $display_links_string;
-    }
-
-// display number of total products found
-    function display_count($text_output) {
-      $to_num = ($this-&gt;number_of_rows_per_page * $this-&gt;current_page_number);
-      if ($to_num &gt; $this-&gt;number_of_rows) $to_num = $this-&gt;number_of_rows;
-
-      $from_num = ($this-&gt;number_of_rows_per_page * ($this-&gt;current_page_number - 1));
-
-      if ($to_num == 0) {
-        $from_num = 0;
-      } else {
-        $from_num++;
-      }
-
-      return sprintf($text_output, $from_num, $to_num, $this-&gt;number_of_rows);
-    }
-  }
-?&gt;
<hr /><a name="file23" /><div class="file">
<span class="pathname" id="removed"><a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog">catalog</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes">includes</a>/<a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/functions">functions</a><br /></span>
<div class="fileheader" id="removed"><big><b>database.php</b></big> <small id="info">removed after <a href="http://cvs.oscommerce.com/viewcvs.cgi/catalog/catalog/includes/functions/database.php?rev=1.23&amp;content-type=text/vnd.viewcvs-markup">1.23</a></small></div>
<pre class="diff"><small id="info">diff -N database.php
--- /tmp/cvsAAA7Aaqf2	Mon Mar  7 11:04:41 2005
+++ /dev/null	Mon Mar  7 11:04:40 2005
@@ -1,142 +0,0 @@
</small></pre><pre class="diff" id="removed">-&lt;?php
-/*
-  $Id$
-
-  osCommerce, Open Source E-Commerce Solutions
-  http://www.oscommerce.com
-
-  Copyright (c) 2003 osCommerce
-
-  Released under the GNU General Public License
-*/
-
-  function tep_db_connect($server = DB_SERVER, $username = DB_SERVER_USERNAME, $password = DB_SERVER_PASSWORD, $database = DB_DATABASE, $link = 'db_link') {
-    global $$link;
-
-    if (USE_PCONNECT == 'true') {
-      $$link = mysql_pconnect($server, $username, $password);
-    } else {
-      $$link = mysql_connect($server, $username, $password);
-    }
-
-    if ($$link) mysql_select_db($database);
-
-    return $$link;
-  }
-
-  function tep_db_close($link = 'db_link') {
-    global $$link;
-
-    return mysql_close($$link);
-  }
-
-  function tep_db_error($query, $errno, $error) {
-    die('&lt;font color="#000000"&gt;&lt;b&gt;' . $errno . ' - ' . $error . '&lt;br&gt;&lt;br&gt;' . $query . '&lt;br&gt;&lt;br&gt;&lt;small&gt;&lt;font color="#ff0000"&gt;[TEP STOP]&lt;/font&gt;&lt;/small&gt;&lt;br&gt;&lt;br&gt;&lt;/b&gt;&lt;/font&gt;');
-  }
-
-  function tep_db_query($query) {
-    global $osC_Database;
-
-    return $osC_Database-&gt;simpleQuery($query);
-  }
-
-  function tep_db_perform($table, $data, $action = 'insert', $parameters = '', $link = 'db_link') {
-    reset($data);
-    if ($action == 'insert') {
-      $query = 'insert into ' . $table . ' (';
-      while (list($columns, ) = each($data)) {
-        $query .= $columns . ', ';
-      }
-      $query = substr($query, 0, -2) . ') values (';
-      reset($data);
-      while (list(, $value) = each($data)) {
-        switch ((string)$value) {
-          case 'now()':
-            $query .= 'now(), ';
-            break;
-          case 'null':
-            $query .= 'null, ';
-            break;
-          default:
-            $query .= '\'' . tep_db_input($value) . '\', ';
-            break;
-        }
-      }
-      $query = substr($query, 0, -2) . ')';
-    } elseif ($action == 'update') {
-      $query = 'update ' . $table . ' set ';
-      while (list($columns, $value) = each($data)) {
-        switch ((string)$value) {
-          case 'now()':
-            $query .= $columns . ' = now(), ';
-            break;
-          case 'null':
-            $query .= $columns .= ' = null, ';
-            break;
-          default:
-            $query .= $columns . ' = \'' . tep_db_input($value) . '\', ';
-            break;
-        }
-      }
-      $query = substr($query, 0, -2) . ' where ' . $parameters;
-    }
-
-    return tep_db_query($query, $link);
-  }
-
-  function tep_db_fetch_array($db_query) {
-    return mysql_fetch_array($db_query, MYSQL_ASSOC);
-  }
-
-  function tep_db_num_rows($db_query) {
-    return mysql_num_rows($db_query);
-  }
-
-  function tep_db_data_seek($db_query, $row_number) {
-    return mysql_data_seek($db_query, $row_number);
-  }
-
-  function tep_db_insert_id() {
-    return mysql_insert_id();
-  }
-
-  function tep_db_free_result($db_query) {
-    return mysql_free_result($db_query);
-  }
-
-  function tep_db_fetch_fields($db_query) {
-    return mysql_fetch_field($db_query);
-  }
-
-  function tep_db_output($string) {
-    return htmlspecialchars($string);
-  }
-
-  function tep_db_input($string, $link = 'db_link') {
-    global $$link;
-
-/*
-    if (function_exists('mysql_real_escape_string')) {
-      return mysql_real_escape_string($string, $$link);
-    } elseif (function_exists('mysql_escape_string')) {
-      return mysql_escape_string($string);
-    }
-*/
-
-    return addslashes($string);
-  }
-
-  function tep_db_prepare_input($string) {
-    if (is_string($string)) {
-      return trim(tep_sanitize_string(stripslashes($string)));
-    } elseif (is_array($string)) {
-      reset($string);
-      while (list($key, $value) = each($string)) {
-        $string[$key] = tep_db_prepare_input($value);
-      }
-      return $string;
-    } else {
-      return $string;
-    }
-  }
-?&gt;
<center><small><a href="http://www.badgers-in-foil.co.uk/projects/cvsspam/" title="commit -&gt; email">CVSspam</a> 0.2.9</small></center>
</body></html>


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click