Guest User

Untitled

a guest
Mar 16th, 2018
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.21 KB | None | 0 0
  1. <?PHP
  2. session_start();
  3.  
  4. include("config.php");
  5.  
  6. if($_SESSION['badgeshop']) {
  7.  
  8. $badgeid = mysql_real_escape_string(strip_tags($_GET['id']));
  9.  
  10. $b1 = mysql_query("SELECT * FROM badgeshop WHERE id='$badgeid'");
  11.  
  12. while($badgerow = mysql_fetch_assoc($b1)){
  13.  
  14. $price = $badgerow['price'];
  15. $badgecode = $badgerow['badgecode'];
  16.  
  17. }
  18.  
  19. $getuserinfo = mysql_query("SELECT * FROM users WHERE username='".$_SESSION['badgeshop']."'");
  20. while($userrow = mysql_fetch_assoc($getuserinfo)) {
  21.  
  22. $coins = $userrow['credits'];
  23. $userid = $userrow['id'];
  24.  
  25. }
  26.  
  27. $getting = mysql_query("SELECT * FROM user_badges WHERE user_id='$userid' AND badge_id='$badgecode'");
  28. $numming = mysql_num_rows($getting);
  29.  
  30. $existing = mysql_num_rows($b1);
  31.  
  32. if($existing!=0){
  33.  
  34. if($numming==0){
  35.  
  36. if($coins<$price){
  37.  
  38. header("Location: index.php?error=4");
  39.  
  40. }
  41. else
  42.  
  43. $credits = mysql_query("UPDATE users SET credits = credits - $price WHERE id='$userid'");
  44. $sql = "INSERT INTO user_badges VALUES('$userid','$badgecode','0')";
  45. $badge = mysql_query($sql);
  46. header("Location: index.php?success=1");
  47.  
  48. }
  49. else
  50. header("Location: index.php?error=2");
  51. }
  52. else
  53. header("Location: index.php?error=5");
  54.  
  55. }
  56. else
  57. header("Location: index.php?error=6");
  58.  
  59. ?>
Add Comment
Please, Sign In to add comment