Файл: gamele.ru/gameplay/ajax/store_ajax.php
Строк: 64
<?
session_start();
include($_SERVER["DOCUMENT_ROOT"]."/includes/config.inc.php");
include(DROOT."/includes/functions.php");
$pers = GetUser();
if($_GET['act'] == '1'){
$GetItem = mysql_fetch_assoc(mysql_query("SELECT * FROM `invent` WHERE `img` = 'fishing/".$_GET['id'].".gif' and `pl_id` = '".$pers['id']."'"));
$forsell=mysql_query("SELECT * FROM `invent` WHERE `invent`.`pl_id`='".$pers['id']."' AND `invent`.`protype`='".$GetItem['protype']."'");
$sum=0;
$numrow=mysql_num_rows($forsell);
if($numrow>0){
while($row = mysql_fetch_array($forsell)){
if($price<1){$price=1;}
$sum+=$price = round(($GetItem['price']),2);
}
}
mysql_query("DELETE FROM `invent` WHERE `pl_id`='".$pers['id']."' AND `protype`='".$GetItem['protype']."'");
mysql_query("UPDATE `user` SET `nv`=`nv`+'".$sum."' WHERE `id`='".$pers['id']."' LIMIT 1;");
mysql_query("UPDATE `res_birja` SET `min_sclad`=`min_sclad`+'".$_GET['mas']."' WHERE `protype`='".$GetItem['protype']."'");
mysql_query("INSERT INTO `chat` (`time`,`login`,`dlya`,`msg`) VALUES ('".time()."','sys','<".$pers['login'].">','".addslashes("top.frames['chmain'].add_msg('<font class=chattime> ".date("H:i:s")." </font><font color=000000><font color=#cc0000><b>Системная информация!</b></font> Вы успешно продали <b>".$GetItem['ItemName']."</b> ".$numrow." шт. за ".$sum." ER.<BR>'+'');")."');");
}
if($pers['loc'] == '52'){
$ITEM=mysql_fetch_assoc(mysql_query('SELECT `invent`.*,`items`.* FROM `items` INNER JOIN `invent` ON `items`.`id` = `invent`.`protype` WHERE `pl_id`="'.$pers['id'].'" AND `items`.`type`="w69" AND `items`.`count`="0" AND `items`.`slot`="0"'));
$query = mysql_query("SELECT * FROM `res_birja` WHERE `type`='STORE'");
$ShowItems = 'STORE@'.vCode().'';
while($row = mysql_fetch_assoc($query))
{
$count = mysql_num_rows(mysql_query("SELECT `invent`.*, `items`.* FROM `items` INNER JOIN `invent` ON `items`.`id` = `invent`.`protype` WHERE `pl_id`='".$pers['id']."' and `items`.`type`='w69' and `items`.`id`='".$row['protype']."'"));
$sum=$ITEM['massa']*$count;
$ShowItems .= '@'.$row['img'].'|'.$row['name'].'|'.number_format($row['nv/massa'], 2, '.', '').'|'.$row['min_sclad'].'/'.$row['max_sclad'].'|'.$row['spros'].'|'.$sum.'|'.(($sum>'0')?''.vCode().'':'').'|'.time().'';
}
echo substr($ShowItems,0,strlen($ShowItems)-1);
}
?>