Файл: test.masteram.us/comm/pov_user.php
Строк: 42
<?php
include '../Core.php';
if(isset($_GET['id'])){
$soo = intval($_GET['id']);
}else{
header("Location: /index.php");
}
$uid = intval($_GET['uid']);
$admin = mysql_fetch_array(mysql_query("SELECT * FROM `community_user_incomm` WHERE `cid` = '$soo' AND `uid` = '".$user['id']."'"));
$set['title'] = 'Повышение участника & '.$_SERVER['HTTP_HOST'];
include_once '../sys/inc/thead.php';
title();
$comm = mysql_fetch_array(mysql_query('SELECT * FROM `community_comm` WHERE `id` = '.$soo.' LIMIT 1'));
$user_comm = mysql_fetch_array(mysql_query('SELECT * FROM `community_user_incomm` WHERE `cid` = '.$soo.' AND `uid` = '.$uid.' LIMIT 1'));
if(!isset($user)){
echo '<div class="err">Доступ закрыт.</div>';
}else if($soo==0 || $soo<0){
echo '<div class="err">Иди нахуй! Хакер недоношеный!</div>';
}else if($soo!=$comm['id']){
echo '<div class="err">Сообщество не найдено.</div>';
}else if($admin['priv']!=2){
echo '<div class="err">Доступ закрыт.</div>';
}else if($user_comm['uid']!=$uid){
echo '<div class="err">Данный пользователь не участвует в сообществе</div>';
}else if(mysql_result(mysql_query("SELECT COUNT(*) FROM `comm_ban` WHERE `id_user` = '$user[id]' AND `id_comm` = '$soo' AND `time` > '$time'"), 0)!=0){
header('Location: ban.php?id='.$soo);
}else{
if($_GET['act']=='adm'){
mysql_query("UPDATE `community_user_incomm` SET `priv` = '2' WHERE `uid` = '$uid' AND `cid` = '$soo'");
mysql_query("OPTIMIZE TABLE `community_user_incomm`");
header("Location: list_user.php?id=$soo");
}else if($_GET['act']=='del_adm'){
mysql_query("UPDATE `community_user_incomm` SET `priv` = '0' WHERE `uid` = '$uid' AND `cid` = '$soo'");
mysql_query("OPTIMIZE TABLE `community_user_incomm`");
header("Location: list_user.php?id=$soo");
}else if($_GET['act']=='mod'){
mysql_query("UPDATE `community_user_incomm` SET `priv` = '1' WHERE `uid` = '$uid' AND `cid` = '$soo'");
mysql_query("OPTIMIZE TABLE `community_user_incomm`");
header("Location: list_user.php?id=$soo");
}else if($_GET['act']=='del_mod'){
mysql_query("UPDATE `community_user_incomm` SET `priv` = '0' WHERE `uid` = '$uid' AND `cid` = '$soo'");
mysql_query("OPTIMIZE TABLE `community_user_incomm`");
header("Location: list_user.php?id=$soo");
}
}
include_once '../sys/inc/tfoot.php';
?>