diff --git a/pandora_console/operation/reporting/graph_viewer.php b/pandora_console/operation/reporting/graph_viewer.php index c518598f38..7584396778 100644 --- a/pandora_console/operation/reporting/graph_viewer.php +++ b/pandora_console/operation/reporting/graph_viewer.php @@ -29,18 +29,24 @@ if (comprueba_login() != 0) { // Delete module SQL code if (isset($_GET["delete"])){ - $id = $_GET["delete"]; - $sql = "DELETE FROM tgraph_source WHERE id_graph = $id"; - if ($res=mysql_query($sql)) - $result = "

".$lang_label["delete_ok"]."

"; - else - $result = "

".$lang_label["delete_no"]."

"; - $sql = "DELETE FROM tgraph WHERE id_graph = $id"; - if ($res=mysql_query($sql)) - $result = "

".$lang_label["delete_ok"]."

"; - else - $result = "

".$lang_label["delete_no"]."

"; - echo $result; + if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1)) { + $id = $_GET["delete"]; + $sql = "DELETE FROM tgraph_source WHERE id_graph = $id"; + if ($res=mysql_query($sql)) + $result = "

".$lang_label["delete_ok"]."

"; + else + $result = "

".$lang_label["delete_no"]."

"; + $sql = "DELETE FROM tgraph WHERE id_graph = $id"; + if ($res=mysql_query($sql)) + $result = "

".$lang_label["delete_ok"]."

"; + else + $result = "

".$lang_label["delete_no"]."

"; + echo $result; + } else { + audit_db($id_usuario,$REMOTE_ADDR, "ACL Violation","Trying to delete a graph from access graph builder"); + include ("general/noaccess.php"); + exit; + } } @@ -143,7 +149,7 @@ echo "

".$lang_label["reporting"]." > "; echo $lang_label["custom_graph_viewer"]."

"; echo ""; echo ""; }
".$lang_label["graph_name"]."".$lang_label["description"]."".$lang_label["view"]; -if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1)) +if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_usuario)==1)) echo ""; $color=1; @@ -166,7 +172,7 @@ while ($row = mysql_fetch_array($res)){ $id_graph = $row["id_graph"]; echo ""; - if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1)) { + if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_usuario)==1)) { echo "'; echo "