Файл: public_html/modules/padmin/change_dest.php
Строк: 61
<?php
/**********************************
* @package: PerfCMS *
* @year: 2012 *
* @author: Artas *
* @link: http://perfcms.net *
* ------------------------------- *
* @package: PerfCMS Ultra *
* @year: 2013 *
* @author: wanya26ua & Tesla *
* @link: http://perfclub.ru *
**********************************/
$locate = 'in_padmin';
$user_id = abs(intval($_GET['user_id']));
if(isset($user) && $user['level'] >= 5 && isset($_GET['user_id']) && $user['id'] != $_GET['user_id'] && $db->query("SELECT level FROM `users` WHERE `id` = '". $_GET['user_id'] ."'")->fetchColumn() != 7) {
$user_level = $db->query("SELECT level FROM `users` WHERE `id` = '".abs(intval($_GET['user_id'])) ."'")->fetchColumn();
$title = $lang->word('change_dest');
require_once(SYS.'/view/header.php');
$tpl->div('title', $lang->word('change_dest').' '.tnick($_GET['user_id']));
if(isset($_POST['save']) && $_GET['act']== 'save') {
$level = abs(intval($_POST['level']));
$db->query("UPDATE `users` SET `level` = '". $level."' WHERE `id` = '".abs(intval($_GET['user_id'])) ."'");
$tpl->div('menu', $lang->word('succ_save'));
$tpl->div('block', img('nav.png') . '<a href="/user/'.abs(intval($_GET['user_id'])) .'/">'.$lang->word('back').'</a><br/>'. img('admin.png') .'<a href="/padmin/">'. $lang->word('padmin') .'</a><br/>'. HICO .'<a href="/">'. $lang->word('home') .'</a>');
require_once(SYS.'/view/footer.php');
exit;
}
echo '<div class="post">
<form action="/padmin/change-dest/'.$user_id.'/?act=save" method="post">
<b>'. $lang->word('change_dest') .'</b>:<br/>
<select name="level">';
echo '<option value="1" '.($user_level==1 ? 'selected="selected"':NULL).'>'. level(1).'</option>';
echo '<option value="2" '.($user_level==2 ? 'selected="selected"':NULL).'>'. level(2).'</option>';
echo '<option value="3" '.($user_level==3 ? 'selected="selected"':NULL).'>'. level(3).'</option>';
echo '<option value="4" '.($user_level==4 ? 'selected="selected"':NULL).'>'. level(4).'</option>';
echo '<option value="5" '.($user_level==5 ? 'selected="selected"':NULL).'>'. level(5).'</option>';
echo '<option value="6" '.($user_level==6 ? 'selected="selected"':NULL).'>'. level(6).'</option>';
echo '</select><br/>
<input type="submit" name="save" value="'. $lang->word('save').'" />
</form>
</div>';
$tpl->div('block', img('admin.png') .'<a href="/padmin/">'. $lang->word('padmin') .'</a><br/>'. HICO .'<a href="/">'. $lang->word('home') .'</a>');
require_once(SYS.'/view/footer.php');
} else { header('Location: /'); }
?>