Файл: vsime.com/polls/inc/act_edit.php
Строк: 35
<?
switch(@$_GET['case']):
case 'diary':
$diary = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `diary` WHERE `id` = '".intval(@$_GET['id_object'])."'"));
if (!@$diary['id']) {
$title .= ' - Ошибка!';
ex_head();
show_errors("Обьект не найден!");
ex_foot();
}
$ank = profile($diary['id_user']);
if ($ank['id'] != $user['id'] && !isset($moderate_diary))access_denied();
include('../diary/inc/configs.php');
if ($diary['poll'] == 0)include('inc/poll_diary_new.php');
else include('inc/poll_diary_edit.php');
break;
case 'topic':
$topic = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `forum` WHERE `id` = '".intval(@$_GET['id_object'])."' AND `type` = 'topic'"));
if (!@$topic['id']) {
$title .= ' - Ошибка!';
ex_head();
show_errors("Обьект не найден!");
ex_foot();
}
$ank = profile($topic['id_user']);
if (!isset($moderate_forum))access_denied();
if ($topic['poll'] == 0)include('inc/poll_topic_new.php');
else include('inc/poll_topic_edit.php');
break;
case 'comm_topic':
$comm = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `comm` WHERE `id` = '".intval($_GET['comm_id'])."'"));
if (!$comm['id']) {
$title .= ' - Ошибка!';
ex_head();
show_errors("Сообщество не найдено!");
ex_foot();
}
$topic = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `forum` WHERE `id` = '".intval(@$_GET['id_object'])."' AND `type` = 'topic' AND `id_comm` = '$comm[id]'"));
if (!@$topic['id']) {
$title .= ' - Ошибка!';
ex_head();
show_errors("Обьект не найден!");
ex_foot();
}
$comm_cat = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `forum` WHERE `id` = '$topic[id_cat]' AND `id_comm` = '$comm[id]'"));
@$uinc = mysqli_fetch_array(mysqli_query($dbi, "SELECT * FROM `comm_users` WHERE `id_user` = '$user[id]' AND `id_comm` = '$comm[id]'"));
$ank = profile($comm['id_user']);
if ($ank['id']!=$user['id'] && $uinc['access']=='user')access_denied();
if ($topic['poll'] == 0)include('inc/poll_comm_topic_new.php');
else include('inc/poll_comm_topic_edit.php');
break;
default:
header("Location: /");
break;
endswitch;
?>