Ok, try the following:
In file ./includes/dl_functions.php find:
PHP Code:
$sqlstring .= " `latest[".($i+1)."]` = '".$array['name'][$i]."', `latestid[".($i+1)."]` = '".$array['id'][$i]."', `latestval[".($i+1)."]` = '".$array['value'][$i]."'";
and replace by:
PHP Code:
$sqlstring .= " `latest[".($i+1)."]` = '".addslashes($array['name'][$i])."', `latestid[".($i+1)."]` = '".$array['id'][$i]."', `latestval[".($i+1)."]` = '".$array['value'][$i]."'";
Find:
PHP Code:
$sqlstring .= " `popular[".($i+1)."]` = '".$array['name'][$i]."', `popularid[".($i+1)."]` = '".$array['id'][$i]."', `popularval[".($i+1)."]` = '".$array['value'][$i]."'";
Replace by:
PHP Code:
$sqlstring .= " `popular[".($i+1)."]` = '".addslashes($array['name'][$i])."', `popularid[".($i+1)."]` = '".$array['id'][$i]."', `popularval[".($i+1)."]` = '".$array['value'][$i]."'";
Find:
PHP Code:
$sqlstring .= " `contrib[".($i+1)."]` = '".$array['name'][$i]."', `contribid[".($i+1)."]` = '".$array['id'][$i]."', `contribval[".($i+1)."]` = '".$array['value'][$i]."'";
Replace by:
PHP Code:
$sqlstring .= " `contrib[".($i+1)."]` = '".addslashes($array['name'][$i])."', `contribid[".($i+1)."]` = '".$array['id'][$i]."', `contribval[".($i+1)."]` = '".$array['value'][$i]."'";