View file wu-engine/wu-actions/eshop_item_new.php

File size: 1.22Kb
<?php
require_once('../wu_init.php');
if (!wu_token()) { exit('wu-error'); }
if (!USER_LOGGED) { exit('3'); }

if(isset($_POST['cat']) && isset($_POST['inf']) && isset($_POST['ty']) && isset($_POST['sec']) && isset($_POST['co']) && isset($_POST['ti']) && isset($_POST['ts']) && isset($_POST['tf'])){
if(!empty($_POST['cat']) && !empty($_POST['co']) && !empty($_POST['ti']) && !empty($_POST['ts']) && !empty($_POST['tf'])){
$cat = intval($_POST['cat']);
$inf = intval($_POST['inf']);
$ty = intval($_POST['ty']);
$sec = mysqli_real_escape_string($connect_db, $_POST['sec']);
$co = mysqli_real_escape_string($connect_db, $_POST['co']);
$ti = htmlspecialchars(mysqli_real_escape_string($connect_db, $_POST['ti']));
$ts = mysqli_real_escape_string($connect_db, $_POST['ts']);
$tf = mysqli_real_escape_string($connect_db, $_POST['tf']);
if ($_POST['co'] < 1) { exit('4'); }
if ($cat < 1 || $cat > 9) { exit('3'); }
if ($inf < 0 || $inf > 1) { exit('3'); }
if ($ty < 0 || $ty > 1) { exit('3'); }
if ($inf == 1) { $ty = '1'; }
mysqli_query($connect_db, "INSERT INTO `".DB_PREFIX."_es` (usr,inf,ty,cat,co,ti,ts,tf,sec,dt) VALUES ('$u_id','$inf','$ty','$cat','$co','$ti','$ts','$tf','$sec','$dt')");
exit('1');
} else { exit('0'); }
} else { exit('3'); }
?>