Index: trunk/admin/config/addtheme_templates.php =================================================================== diff -u -r375 -r384 --- trunk/admin/config/addtheme_templates.php (.../addtheme_templates.php) (revision 375) +++ trunk/admin/config/addtheme_templates.php (.../addtheme_templates.php) (revision 384) @@ -108,7 +108,7 @@ $objEditItems->EnablePaging = FALSE; //Multiedit init -$en = (int)$_GET["en"]; +$en = (int)GetVar('en'); $objEditItems->Query_Item("SELECT * FROM ".$objEditItems->SourceTable); $itemcount=$objEditItems->NumItems(); @@ -226,23 +226,17 @@ $sql = "SELECT t.*,t.Description as Description, ELT(t.FileType+1,'".admin_language("la_Text_BuiltIn")."','".admin_language("la_Text_Custom")."') as Type "; $sql .= "FROM ".GetTablePrefix()."ThemeFiles as t WHERE t.ThemeId=".$c->Get("ThemeId")." "; -if(strlen($where)) - $sql .= "AND ".$where." "; -if(strlen($order)) - $sql .= "ORDER BY ".$order." "; + +if( strlen($where) ) $sql .= ' AND '.$where.' '; +if( strlen($order) ) $sql .= 'ORDER BY '.$order.' '; $limit = ' '.$objListView->GetLimitSQL();; $sql .= $limit; $c->VerifyTemplates($where,$order,$limit); // slow down process -if(isset($_GET["lpn"])) - $objSession->SetVariable("Page_Template",$_GET["lpn"]); +if( GetVar('lpn') !== false ) $objSession->SetVariable("Page_Template",$_GET["lpn"]); - - - - $objThemeFiles->Query_Item($sql); $ThemeDir = strtolower($c->Get("Name")).$pathchar; Index: trunk/kernel/action.php =================================================================== diff -u -r375 -r384 --- trunk/kernel/action.php (.../action.php) (revision 375) +++ trunk/kernel/action.php (.../action.php) (revision 384) @@ -28,7 +28,7 @@ echo ''.$src.''.$key.''.print_r($value, true).''; } echo ''; - echo 'Reload Frame'; + echo 'Reload Frame
'; } unset($script, $skip_debug); } Index: trunk/kernel/include/theme.php =================================================================== diff -u -r375 -r384 --- trunk/kernel/include/theme.php (.../theme.php) (revision 375) +++ trunk/kernel/include/theme.php (.../theme.php) (revision 384) @@ -194,7 +194,7 @@ $this->Clear(); $this->ThemeId=$id; $sql = "SELECT * FROM ".$this->SourceTable. " WHERE ThemeId=$id "; - if(strlen(trim($where))) $sql .= $where." "; + if(strlen(trim($where))) $sql .= ' AND '.$where." "; if(strlen(trim($orderBy))) $sql .= "ORDER BY $orderBy"; if(strlen(trim($limit))) $sql .= $limit;