<?php
include (dirname (__file__) .'/globals.php');
if (isset ($_POST['user']) ) {
$check = $db->query("SELECT `userid` FROM `users` WHERE ( `userid` = ".abs(@intval($_POST['user']))." ) ");
if (!$db->num_rows ($check) ) {
echo 'Error: User doesn\'t exist.';
$h->endpage();
exit;
}
if ($ir['money'] < 1000) {
echo 'Invalid Command.
You do not have enough money to use this.
> [url="index.php"]Go Home[/url]';
$h->endpage();
exit;
} else {
$db->query ('UPDATE `users` SET `new_mail` = `new_mail` + '.abs(@intval($_POST['newmail'])).' WHERE( `userid` = '.abs(@intval($_POST['user'])).' )' );
$db->query ('UPDATE `users` SET `money` = `money` - 1000 WHERE ( `userid` = '.$userid.' )' );
echo 'Prank Done';
}
} else {
echo '
<h3>Mailpranking User<h3>
This user will have a set number of new mail, this will cost you $1000</p>
<form action="'.basename(__file__).'" method="post">
<span>User:</span> '.user_dropdown($c,"user",$_GET['userid']).'
<span>Number:</span> <input type="text" name="newmail" />
<input type="submit" value="Prank \'em" />
</form>
';
}
$h->endpage();
?>
You also may want to check if the user exists aswell...