- 01
- 02
- 03
- 04
- 05
- 06
- 07
- 08
- 09
- 10
- 11
- 12
- 13
- 14
- 15
- 16
case 'top':
$nick=$_GET["nick"];
$pass=$_GET["pass"];
mysql_query("SELECT * FROM users WHERE nick = '$nick' and pass = '$pass'");
if (@mysql_affected_rows($link)!=0){
$sub=$_POST["sub"];
$text=addslashes(strip_tags(nl2br($_POST["text"]),'<br>'));
$ip=$_SERVER["REMOTE_ADDR"];
$cat_id=$_GET["cat_id"];
mysql_query("insert into f_subject values (NULL, '$sub', '$nick', '0' , '$nick', NOW(), NOW(), '$ip' , '$text', '$cat_id')");
$row= mysql_fetch_array(mysql_query("SELECT *FROM f_cat WHERE id ='$cat_id'"));
$topics=$row["topics"]+1;
mysql_query("UPDATE f_cat SET topics='$topics' WHERE id ='$cat_id'");
}
Header("Location: index.php?cat=".$cat_id);
break;
guest 30.04.2009 15:54 # 0
чел не слышал про иньекции.