aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorcassiopc <cassiopc@gmail.com>2012-09-04 19:49:42 +0000
committercassiopc <cassiopc@gmail.com>2012-09-04 19:49:42 +0000
commita3e75b0020ddeda2f8c376135bb9f728d9f0946d (patch)
tree38590c7f91998caf31fc4a42d4785237e2e8ff9c
parent2948fe8d6055f6dfe6289e64bce426b5e0bb552f (diff)
downloadboca-a3e75b0020ddeda2f8c376135bb9f728d9f0946d.tar.gz
boca-a3e75b0020ddeda2f8c376135bb9f728d9f0946d.zip
password update problem in admin tab
-rw-r--r--boca-1.5.0/src/admin/user.php11
1 files changed, 6 insertions, 5 deletions
diff --git a/boca-1.5.0/src/admin/user.php b/boca-1.5.0/src/admin/user.php
index 5e07930..a6a374d 100644
--- a/boca-1.5.0/src/admin/user.php
+++ b/boca-1.5.0/src/admin/user.php
@@ -56,7 +56,8 @@ if (isset($_POST["username"]) && isset($_POST["userfullname"]) && isset($_POST["
MSGError('Admin password is incorrect');
} else {
if ($_POST["passwordn1"] == $_POST["passwordn2"]) {
- $param['pass'] = bighexsub(htmlspecialchars($_POST["passwordn1"]),$a['userpassword']);
+ $param['pass'] =htmlspecialchars($_POST["passwordn1"]);
+// $param['pass'] = bighexsub(htmlspecialchars($_POST["passwordn1"]),$a['userpassword']);
DBNewUser($param);
}
else MSGError ("Passwords don't match.");
@@ -278,11 +279,11 @@ if (isset($_GET["site"]) && isset($_GET["user"]) && is_numeric($_GET["site"]) &&
<script language="JavaScript">
function computeHASH()
{
- document.form3.passwordn1.value = bighexsoma(js_myhash(document.form3.passwordn1.value),js_myhash(document.form3.passwordo.value));
- document.form3.passwordn2.value = bighexsoma(js_myhash(document.form3.passwordn2.value),js_myhash(document.form3.passwordo.value));
+// document.form3.passwordn1.value = bighexsoma(js_myhash(document.form3.passwordn1.value),js_myhash(document.form3.passwordo.value));
+// document.form3.passwordn2.value = bighexsoma(js_myhash(document.form3.passwordn2.value),js_myhash(document.form3.passwordo.value));
document.form3.passwordo.value = js_myhash(js_myhash(document.form3.passwordo.value)+'<?php echo session_id(); ?>');
-// document.form3.passwordn1.value = js_myhash(document.form3.passwordn1.value);
-// document.form3.passwordn2.value = js_myhash(document.form3.passwordn2.value);
+ document.form3.passwordn1.value = js_myhash(document.form3.passwordn1.value);
+ document.form3.passwordn2.value = js_myhash(document.form3.passwordn2.value);
}
</script>