Файл: world-faces.ru/world-faces.ru/incl/friend_act.php
Строк: 49
<?
if (isset($_GET['friend']) && $_GET['friend']=='delete'){
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '$al[id]' LIMIT 1"),0)==0){header("Location: index.php?");exit;}
mysql_query("DELETE FROM `frends` WHERE `user` = '$us[id]' AND `frend` = '$al[id]' LIMIT 1");
mysql_query("DELETE FROM `frends` WHERE `user` = '$al[id]' AND `frend` = '$us[id]' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '$al[id]' AND `to` = '$us[id]' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '$us[id]' AND `to` = '$al[id]' LIMIT 1");
mysql_query("OPTIMIZE TABLE `frends`");
mysql_query("OPTIMIZE TABLE `frends_new`");
$timer = intval($_SERVER['REQUEST_TIME']);
$msb="[b][url=/".$us['id']."]".$us['nick']."[/url][/b] удалил".(($us['pol']==0)?'а':'')." вас из списка [url=/frend.php?id=".$us['id']."/]своих[/url] [url=/frend.php?id=".$al['id']."/]друзей[/url]!";
mysql_query("INSERT INTO `op` (`id_us`,`msg`,`type`,`time`) values('$al[id]', '$msb', 6,'$timer')");
msg ('Обитатель успешно удален из списка ваших друзей');
header ("location: main.php?id=$al[id]");
}
if (isset($_GET['friend']) && $_GET['friend']=='ok'){
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '$al[id]' LIMIT 1"),0)==0){header("Location: index.php?".SID);exit;}
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `frends` WHERE (`user` = '$us[id]' AND `frend` = '$al[id]') OR (`user` = '$al[id]' AND `frend` = '$us[id]') LIMIT 1"),0)==1){header("Location: index.php?".SID);exit;}
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `frends_new` WHERE (`user` = '$us[id]' AND `to` = '$al[id]') OR (`user` = '$al[id]' AND `to` = '$us[id]') LIMIT 1"),0)==1){header("Location: index.php?".SID);exit;}
if ($al['id']==$us['id']){header("Location: index.php?".SID);exit;}
mysql_query("INSERT INTO `frends_new` (`user`, `to`, `time`) values('$us[id]', '$al[id]', '$time')");
mysql_query("OPTIMIZE TABLE `frends_new`");
msg ('Ваше предложение дружбы отправлено обитателю '.$al['nick'].'');
header ("location: main.php?id=$al[id]");
}
$d1sql = mysql_query("SELECT COUNT(*) FROM `frends_new` WHERE (`user` = '$us[id]' AND `to` = '$al[id]') OR (`user` = '$al[id]' AND `to` = '$us[id]') LIMIT 1");
$d2sql = mysql_query("SELECT COUNT(*) FROM `frends` WHERE (`user` = '$al[id]' AND `frend` = '$us[id]') OR (`user` = '$us[id]' AND `frend` = '$al[id]') LIMIT 1");
?>