Файл: vsime.com/comm/inc/act_blist.php
Строк: 88
<?
if(mysqli_num_rows(mysqli_query($dbi, "SELECT * FROM `comm` WHERE `id` = '".intval($_GET['id'])."'"))!=0)
{
$comm=mysqli_query($dbi, "SELECT * FROM `comm` WHERE `id` = '".intval($_GET['id'])."'");
$comm=mysqli_fetch_array($comm);
$cat=mysqli_query($dbi, "SELECT * FROM `comm_cat` WHERE `id` = '$comm[id_cat]'");
$cat=mysqli_fetch_array($cat);
if (mysqli_num_rows(mysqli_query($dbi, "SELECT * FROM `comm_users` WHERE `id_comm` = '$comm[id]' AND `activate` = '1' AND `invite` = '0'"))==0)$comm['id_user']=0;
$ank=profile($comm['id_user']); // sozdak
if($ank['id']==$user['id'] && isset($user) || $uinc['access']=='adm')
{
$links_hist['name'] = "Сообщества / ".($comm['name'])." / Черный список";
$title .= ' - '.htmlspecialchars($comm['name']).' - Черный список'; // Заголовок страницы
ex_head();
if(isset($_GET['add']))
{
if (hsc(@$_GET['mdp'])==$mdp)
{
$ank2=profile(intval($_GET['add']));
if($ank2['id']!=0)
{
if(mysqli_num_rows(mysqli_query($dbi, "SELECT * FROM `comm_blist` WHERE `id_comm` = '$comm[id]' AND `id_user` = '$ank2[id]'"))==0)
{
mysqli_query($dbi, "INSERT INTO `comm_blist` SET `id_comm` = '$comm[id]', `id_user` = '$ank2[id]'");
mysqli_query($dbi, "INSERT INTO `comm_journal` SET `id_comm` = '$comm[id]', `id_user` = '$ank2[id]', `id_ank` = '$user[id]', `type` = 'in_blist', `time` = '$time'");
}
else $error[]="Пользователь уже находится в Черном списке сообщества";
}
else $error[]="Пользователь не найден.";
} else hacked_by_Killer();
}
if(isset($_GET['delete']))
{
if (hsc(@$_GET['mdp'])==$mdp)
{
if(mysqli_num_rows(mysqli_query($dbi, "SELECT * FROM `comm_blist` WHERE `id` = '".intval($_GET['delete'])."' AND `id_comm` = '$comm[id]'"))!=0)
{
$ank2=profile(mysqli_num_rows(mysqli_query($dbi, "SELECT `id_user` FROM `comm_blist` WHERE `id` = '".intval($_GET['delete'])."' AND `id_comm` = '$comm[id]'")));
mysqli_query($dbi, "DELETE FROM `comm_blist` WHERE `id` = '".intval($_GET['delete'])."' AND `id_comm` = '$comm[id]'");
mysqli_query($dbi, "INSERT INTO `comm_journal` SET `id_comm` = '$comm[id]', `id_user` = '$ank2[id]', `id_ank` = '$user[id]', `type` = 'out_blist', `time` = '$time'");
}
} else hacked_by_Killer();
}
if(isset($_POST['nick']) && isset($_POST['submited']))
{
if (hsc(@$_POST['mdp'])==$mdp)
{
$ank2=mysqli_query($dbi, "SELECT * FROM `user` WHERE `nick` = '".my_esc($_POST['nick'])."'");
$ank2=mysqli_fetch_array($ank2);
if($ank2['id']!=0)
{
header("Location:?act=blist&id=$comm[id]&add=$ank2[id]&mdp=$mdp");
exit();
}
else $error[]="Пользователь не найден.";
} else hacked_by_Killer();
}
show_errors();
echo "<form method='POST'>n";
echo "<input type='text' name='nick' value=''> n";
echo "<input type='hidden' name='mdp' value='$mdp'>n";
echo "<input type='submit' name='submited' value='Добавить'>n";
echo "</form>";
$count_results = mysqli_num_rows(mysqli_query($dbi, "SELECT * FROM `comm_blist` WHERE `id_comm` = '$comm[id]'"));
$count_pages = count_pages($count_results);
$page = page();
$start = start_pages();
if ($count_results==0)
{
echo "<div class='list'>n";
echo "Нет пользователей.n";
echo "</div>n";
}
$query=mysqli_query($dbi, "SELECT * FROM `comm_blist` WHERE `id_comm` = '$comm[id]' ORDER BY `time` DESC LIMIT $start, $config[rop]");
while($post=mysqli_fetch_array($query))
{
$ank2=profile($post['id_user']);
echo "<div class='list'>n";
echo "<div class='left'>n";
show_avatar($ank2['id'], 'small');
echo "</div>n";
echo "<div class='pverfl_hid'>n";
echo profile_icon($ank2['id']).profile_nick($ank2['id'], 1).profile_medal($ank2['id']);
echo "<span class='right'><a href='?act=blist&id=$comm[id]&delete=$post[id]&mdp=$mdp'>$config[code_delete]</a></span>n";
echo "</div>n";
echo "<div class='clear'></div>n";
echo "</div>n";
}
pages_show("?act=blist&id=$comm[id]&"); // Вывод страниц
echo "<div class='foot'>n";
echo image_back()." <a href='?act=comm_settings&id=$comm[id]'>В админку</a> | <a href='?act=comm&id=$comm[id]'>В сообщество</a>n";
echo "</div>n";
}
else{header("Location:/index/comm");exit;}
}
else{header("Location:/comm");exit;}
?>