Гг очень по человечески
<?php
If (!isset($_GET['mode']) || !ereg("^[a-z0-9_-]{1,15}$",$_GET['mode'])) $mode=false; else $mode=$_GET['mode'];
switch ($mode){
<?php
$_GET['id']=htmlspecialchars(stripslashes(trim($_GET['id'])));
$_GET['id']=mysql_real_escape_string($_GET['id']);
$result=@mysql_query("SELECT * FROM `inf_zak` WHERE `nomer`='".$_GET['id']."'");
$result2=@mysql_query("SELECT `koment` FROM `inf_zak` WHERE `nomer`='".$_GET['id']."'");
$result3=@mysql_query("SELECT `ssylka` FROM `inf_zak` WHERE `nomer`='".$_GET['id']."'");
$result4=@mysql_query("SELECT * FROM `inf_zak` WHERE `nomer`='".$_GET['id']."'");
Изменил: Lugaro (09.01.2010 / 03:15)