Advertisement
Guest User

Untitled

a guest
Nov 19th, 2013
49
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.35 KB | None | 0 0
  1. <?php
  2. if(!defined('NOWHOS'))
  3. {
  4. define('NOWHOS', true);
  5. }
  6. define('Xukys', true);
  7. require_once '../global.php';
  8. require_once "../includes/class.homes.php";
  9.  
  10. if(isset($_POST["stickers"]))
  11. {
  12.  
  13. $var = explode('/', $_POST['sticker']);
  14. //var_dump($var);
  15. foreach($var as $var_data)
  16. {
  17. if(empty($var_data))
  18. {
  19. break;
  20. }
  21.  
  22. $vardata = explode(':', $var_data);
  23. $xyz = explode(',', $vardata[1]);
  24.  
  25. $sql = mysql_query("SELECT skin FROM site_inventory_items WHERE userId = '" . USER_ID . "' AND id = '" . mysql_real_escape_string($vardata[0]) ."' AND isWaiting = '1' LIMIT 1");
  26. if(mysql_num_rows($sql) > 0)
  27. {
  28. $row = mysql_fetch_array($sql);
  29.  
  30. mysql_query("INSERT INTO homes_items (id, home_id, type, x, y, z, data, skin, owner_id, link) VALUES (NULL, '".USER_ID."', 'sticker', '".mysql_real_escape_string($xyz[0])."', '".mysql_real_escape_string($xyz[1])."', '".mysql_real_escape_string($xyz[2])."', '".$row['skin']."', '', '".USER_ID."', '".mysql_real_escape_string($vardata[0])."');");
  31. mysql_query("UPDATE site_inventory_items SET isWaiting = '0' WHERE id = '".mysql_real_escape_string($vardata[0])."' AND userId = '".USER_ID."' LIMIT 1;");
  32. //echo 'ok';
  33. }
  34. else
  35. {
  36. mysql_query("UPDATE homes_items SET x = '".mysql_real_escape_string($xyz[0])."', y = '".mysql_real_escape_string($xyz[1])."', z = '".mysql_real_escape_string($xyz[2])."' WHERE id = '".mysql_real_escape_string($vardata[0])."' AND owner_id = '".USER_ID."' LIMIT 1");
  37. //echo 'else';
  38. }
  39. }
  40.  
  41.  
  42. }
  43.  
  44. if(isset($_POST["stickienotes"]))
  45. {
  46.  
  47. $varstickienotes = explode('/', $_POST['stickienotes']);
  48. //var_dump($var);
  49. foreach($varstickienotes as $var_datastickienotes)
  50. {
  51. if(empty($var_datastickienotes))
  52. {
  53. break;
  54. }
  55. $vardatastickienotes = explode(':', $var_datastickienotes);
  56. $xyzstickienotes = explode(',', $vardatastickienotes[1]);
  57.  
  58. $sqlstickienotes = mysql_query("SELECT skin FROM site_inventory_items WHERE userId = '" . USER_ID . "' AND id = '" . mysql_real_escape_string($vardatastickienotes[0]) ."' AND isWaiting = '1' LIMIT 1");
  59.  
  60. if(mysql_num_rows($sqlstickienotes) > 0)
  61. {
  62. $rowstickienotes = mysql_fetch_assoc($sqlstickienotes);
  63.  
  64. mysql_query("INSERT INTO homes_items (id, home_id, type, x, y, z, data, skin, owner_id) VALUES (NULL, '".USER_ID."', 'sticker', '".mysql_real_escape_string($xyzstickienotes[0])."', '".mysql_real_escape_string($xyzstickienotes[1])."', '".mysql_real_escape_string($xyzstickienotes[2])."', '".$rowstickienotes['skin']."', '', '".USER_ID."');");
  65. // mysql_query("UPDATE site_inventory_items SET isWaiting = '0' WHERE id = '".mysql_real_escape_string($vardatastickienotes[0])."' AND userId = '".USER_ID."' LIMIT 1");
  66. }
  67. else
  68. {
  69. mysql_query("UPDATE homes_items SET x = '".mysql_real_escape_string($xyzstickienotes[0])."', y = '".mysql_real_escape_string($xyzstickienotes[1])."', z = '".mysql_real_escape_string($xyzstickienotes[2])."' WHERE id = '".mysql_real_escape_string($vardatastickienotes[0])."' AND owner_id = '".USER_ID."' LIMIT 1");
  70. }
  71. }
  72.  
  73.  
  74. }
  75.  
  76. if(isset($_POST["widgets"]))
  77. {
  78.  
  79. $varwidgets = explode('/', $_POST['widgets']);
  80. //var_dump($var);
  81. foreach($varwidgets as $var_datawidgets)
  82. {
  83. if(empty($var_datawidgets))
  84. {
  85. break;
  86. }
  87. $vardatawidgets = explode(':', $var_datawidgets);
  88. $xyzwidgets = explode(',', $vardatawidgets[1]);
  89.  
  90. $sqlwidgets = mysql_query("SELECT skin FROM site_inventory_items WHERE userId = '" . USER_ID . "' AND id = '" . mysql_real_escape_string($vardatawidgets[0]) ."' AND isWaiting = '1' LIMIT 1");
  91.  
  92. if(mysql_num_rows($sqlwidgets) > 0)
  93. {
  94. $rowwidgets = mysql_fetch_assoc($sqlwidgets);
  95.  
  96. //mysql_query("INSERT INTO homes_items (id, home_id, type, x, y, z, data, skin, owner_id) VALUES (NULL, '".USER_ID."', 'sticker', '".mysql_real_escape_string($xyzwidgets[0])."', '".mysql_real_escape_string($xyzwidgets[1])."', '".mysql_real_escape_string($xyzwidgets[2])."', '".$rowwidgets['skin']."', '', '".USER_ID."');");
  97. // mysql_query("UPDATE site_inventory_items SET isWaiting = '0' WHERE id = '".mysql_real_escape_string($vardatawidgets[0])."' AND userId = '".USER_ID."' LIMIT 1");
  98. }
  99. else
  100. {
  101. mysql_query("UPDATE homes_items SET x = '".mysql_real_escape_string($xyzwidgets[0])."', y = '".mysql_real_escape_string($xyzwidgets[1])."', z = '".mysql_real_escape_string($xyzwidgets[2])."' WHERE id = '".mysql_real_escape_string($vardatawidgets[0])."' AND owner_id = '".USER_ID."' LIMIT 1");
  102. }
  103. }
  104.  
  105.  
  106. }
  107.  
  108. if(isset($_POST['background']))
  109. {
  110. $background = $gtfo->cleanWord($_POST['background']);
  111. $bg = explode(':', $_POST['background']);
  112.  
  113. if(is_numeric($bg[0]))
  114. {
  115. $sql = mysql_query("SELECT userId from site_inventory_items WHERE id = '".$bg[0]."'");
  116. $data = mysql_fetch_array($sql);
  117. //echo $bg[0];
  118.  
  119. if(mysql_num_rows($sql) > 0)
  120. {
  121. if($data['userId'] == USER_ID)
  122. {
  123.  
  124. mysql_query("UPDATE homes SET bgimage = '".$bg[1]."' WHERE home_id = '".USER_ID."'");
  125. //echo 'ok';
  126. }
  127. }
  128.  
  129. }
  130.  
  131.  
  132.  
  133. }
  134.  
  135. unset($_SESSION['startSessionEditHome']);
  136. ?>
  137. <script language="JavaScript" type="text/javascript">
  138. waitAndGo('/home/<?php echo $_SESSION['UBER_USER_N']; ?>');
  139. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement