Exemple #1
0
 $youtube = $youtube['v'];
 $title_short = PHP_slashes(htmlspecialchars(strip_tags($_POST['title_short'])));
 $chpu = PHP_slashes(htmlspecialchars(strip_tags($_POST['chpu'])));
 $meta_desc = PHP_slashes(htmlspecialchars(strip_tags($_POST['meta_desc'])));
 $meta_key = PHP_slashes(htmlspecialchars(strip_tags($_POST['meta_key'])));
 $framecolor = PHP_slashes(htmlspecialchars(strip_tags($_POST['framecolor'])));
 $rubcolor = PHP_slashes(htmlspecialchars(strip_tags($_POST['rubcolor'])));
 $color = array('frame' => $framecolor, 'rubric' => $rubcolor);
 $fb_sql = PHP_slashes(htmlspecialchars(strip_tags($_POST['fbf'])));
 $info = serialize($_POST['info']);
 $color = serialize($color);
 $sponsored = intval($_POST['sponsored']);
 $phg = PHP_slashes(htmlspecialchars(strip_tags($_POST['phg'])));
 $slide_type = isset($_POST['slide_type']) > 0 ? '1' : '0';
 if ($chpu == $num['chpu']) {
     $chpu = generate_ge($title);
 }
 $SQL_PHOTO = '';
 $cat = intval($_POST['cat']);
 if (empty($_POST['copy']['title']) && !empty($_POST['copy']['url'])) {
     $error[0] = 'გთხვოთ, ჩაწეროთ წყაროს სათაური.';
 } elseif (!empty($_POST['copy']['title']) && empty($_POST['copy']['url'])) {
     $error[0] = 'გთხვოთ, ჩაწეროთ წყაროს ბმული.';
 } else {
     $copy = serialize($_POST['copy']);
 }
 $numbers = array();
 for ($i = 0; $i <= 100; $i++) {
     if ($i < 10) {
         $numbers[] = '0' . $i . '';
     } else {
Exemple #2
0
        $sql = "DELETE FROM `#__category` WHERE `#__category`.`id` = " . intval($_GET['delete']) . " LIMIT 1";
        $DB->execute($sql);
        header('Location: ?component=category&sec=' . $_GET['sec'] . '');
    }
}
if (get_access('admin', 'category', 'edit', false)) {
    $name = htmlspecialchars(strip_tags($_POST['name']));
    $stat = intval($_POST['test']);
    $chpu = htmlspecialchars(strip_tags($_POST['chpu']));
    $authors = serialize($_POST['author']);
    $cat = htmlspecialchars(strip_tags($_POST['cat']));
    $design = intval($_POST['design']);
    $bade = intval($_POST['bade']);
    $type = intval($_POST['type']);
    if ($chpu == '') {
        $chpu = generate_ge($name);
    }
    if ($_POST['edit'] == 1) {
        if ($err == 0) {
            if ($bade > 0 && $_GET['edit'] > 0) {
                $time = time();
                $DB->execute('DELETE FROM #__bade WHERE cat_id=' . intval($_GET['edit']));
            }
            $sql = "UPDATE `#__category` SET `name` = '" . $name . "',`test` = '" . $stat . "', `cat_chpu` = '" . $chpu . "', `users` = '" . $authors . "', `design` = '" . $design . "',`type`='" . $type . "',`bade`='" . $bade . "'\r\n\t\t\tWHERE `id`='" . intval($_POST['idd']) . "' LIMIT 1; ";
            $DB->execute($sql);
            $message[0] = 'valid';
            $message[1] = 'ჩანაწერი წარმატებით შეიცვალა';
        }
    }
    if ($_POST['add'] == 1) {
        if (!empty($name)) {