Файл: vxas.ru/duel/inc.php
Строк: 124
<?
$ql=mysql_query("SELECT * FROM `duel` WHERE `act` = '1' AND `time` < '".mysql_real_escape_string($time)."' ORDER BY time");
while ($finish = mysql_fetch_array($ql))
{
$vote=mysql_result(mysql_query("SELECT COUNT(*) FROM `duel_vote` WHERE `id_duel` = '".mysql_real_escape_string($finish[id])."' AND `id_opponent` = '".mysql_real_escape_string($finish[user])."'"),0);
$vote2=mysql_result(mysql_query("SELECT COUNT(*) FROM `duel_vote` WHERE `id_duel` = '".mysql_real_escape_string($finish[id])."' AND `id_opponent` = '".mysql_real_escape_string($finish[opponent])."'"),0);
if($vote>$vote2){
mysql_query("UPDATE `user` SET `rating`=`rating`+'".mysql_real_escape_string($vote)."' WHERE `id`='".mysql_real_escape_string($finish['user'])."'");
mysql_query("UPDATE `duel` SET `finish` = '".mysql_real_escape_string($finish['user'])."', `act`='2' WHERE `id`='".mysql_real_escape_string($finish['id'])."'");
$msg = 'Поздравляем, вы выиграли в дуэли и ваш рейтинг вырос на '.htmlspecialchars($vote).'!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values ('0', '".mysql_real_escape_string($finish['user'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
$msgs = 'Сожалеем вам, но вы проиграли схватку в дуэли!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values ('0', '".mysql_real_escape_string($finish['opponent'])."', '".mysql_real_escape_string($msgs)."', '".mysql_real_escape_string($time)."')");
}
else if(($vote + $vote2) == 0){
$msg = 'К сожалению за вашу дуэль никто не проголосовал!';
mysql_query("UPDATE `duel` SET `act`='2' WHERE `id`='".mysql_real_escape_string($finish['id'])."'");
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values ('0', '".mysql_real_escape_string($finish['user'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values ('0', '".mysql_real_escape_string($finish['opponent'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
}
else if($vote == $vote2){
$rat = ($vote/2);
mysql_query("UPDATE `user` SET `rating`=`rating`+'".mysql_real_escape_string($rat)."' WHERE `id`='".mysql_real_escape_string($finish['user'])."'");
mysql_query("UPDATE `user` SET `rating`=`rating`+'".mysql_real_escape_string($rat)."' WHERE `id`='".mysql_real_escape_string($finish['opponent'])."'");
mysql_query("UPDATE `duel` SET `act`='2' WHERE `id`='".mysql_real_escape_string($finish['id'])."'");
$msg = 'Поздравляем, схватка прошла вничью, и ваш рейтинг вырос на '.htmlspecialchars($rat).'!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".mysql_real_escape_string($finish['user'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".mysql_real_escape_string($finish['opponent'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
}
else if($vote<$vote2){
mysql_query("UPDATE `user` SET `rating`=`rating`+'".mysql_real_escape_string($vote2)."' WHERE `id`='".mysql_real_escape_string($finish['opponent'])."'");
mysql_query("UPDATE `duel` SET `finish` = '".mysql_real_escape_string($finish['opponent'])."', `act`='2' WHERE `id`='".mysql_real_escape_string($finish['id'])."'");
$msg = 'Поздравляем, вы выиграли в дуэли и ваш рейтинг вырос на '.htmlspecialchars($vote2).'!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".mysql_real_escape_string($finish['opponent'])."', '".$mysql_real_escape_string(msg)."', '".mysql_real_escape_string($time)."')");
$msgs = 'Сожалеем вам, но вы проиграли схватку в дуэли!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".mysql_real_escape_string($finish['user'])."', '".mysql_real_escape_string($msgs)."', '".mysql_real_escape_string($time)."')");
}
}
$qld=mysql_query("SELECT * FROM `duel` WHERE `act` = '0' AND `time` < '".mysql_real_escape_string($time)."' ORDER BY time");
while ($exit = mysql_fetch_array($qld))
{
$ald = mysql_fetch_array(mysql_query("SELECT * FROM `user` WHERE `id` = '".mysql_real_escape_string($exit['user'])."' LIMIT 1"));
$msg = 'К сожалению '.htmlspecialchars($ald['nick']).' проигнорировал ваш вызов на дуэль!';
mysql_query("UPDATE `user` SET `balls` = '".mysql_real_escape_string($user['balls']+100)."' WHERE `id` = '".mysql_real_escape_string($exit['user'])."' LIMIT 1");
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".mysql_real_escape_string($exit['user'])."', '".mysql_real_escape_string($msg)."', '".mysql_real_escape_string($time)."')");
mysql_query("DELETE FROM `duel` WHERE `id` = '".mysql_real_escape_string($exit[id])."' LIMIT 1");
}
?>