Файл: test.masteram.us/us_guest/delete.php
Строк: 10
<?
include '../Core.php';
$us_adm=intval($_GET['id']);
if (isset($_GET['id']) && mysql_result(mysql_query("SELECT COUNT(*) FROM `us_guest` WHERE `id` = '".intval($_GET['id'])."'"),0)==1)
{
$post=mysql_fetch_array(mysql_query("SELECT * FROM `us_guest` WHERE `id` = '".intval($_GET['id'])."' LIMIT 1"));
$ank=mysql_fetch_array(mysql_query("SELECT * FROM `user` WHERE `id` = $post[id_user] LIMIT 1"));
if (isset($user) && ($user['level']>$ank['level'] || $user['level']==4 || $user['id']=$us_adm))
mysql_query("DELETE FROM `us_guest` WHERE `id` = '$post[id]'");
}
if (isset($_SERVER['HTTP_REFERER']) && $_SERVER['HTTP_REFERER']!=NULL)
header("Location: ".$_SERVER['HTTP_REFERER']);
else
header("Location: index.php?".SID);
?>