Medlem
|
|
Reg.datum: Jul 2008
Inlägg: 121
|
|
Medlem
Reg.datum: Jul 2008
Inlägg: 121
|
Precis jag har fått ett fall en kille skrev script kod i medlem sidan och det var inte bra.
Kolla nedan!
<?
include 'header.php';
if (isset($_POST['submit'])) {
$avatar = $_POST["avatar"];
$quote = $_POST["quote"];
//insert the values
if (!isset($message)){
$result= mysql_query("UPDATE `grpgusers` SET `avatar`='".$avatar."', `desc`='".$quote."' WHERE `id`='".$user_class->id."'");
echo Message('Your preferences have been saved.');
die();
}
}
?>
<?
if (isset($message)) {
echo Message($message);
}
?>
<style type="text/css">
<!--
.stil2 {font-size: x-small}
-->
</style>
<tr>
<td class="contenthead"> Medlemssida Inställningar: </td>
</tr>
<tr><td class="contentcontent">
<form name='login' method='post'>
<table width='69%' border='0' align='center' cellpadding='0' cellspacing='0'>
<tr>
<td height='28' align="right"></td>
<td>Avatar Bild Adress:</td>
</tr>
<tr>
<td width="28%" height='28' align="right"><span class="stil2"></span></td>
<td width="72%"><font size='2' face='verdana'>
<input name='avatar' type='text' value='<?= $user_class->avatar ?>' size="80">
</font></td>
</tr>
<tr>
<td height='28' align="right"></td>
<td>
Vill du ha en Avatar i din profil? Då gör du så
här. Hittar du en egen bild på webben så fyll i
adressen till den bilden i den adress ruta ovan ex:
Hittar du ingen egen bild så kan du använda våra
ex: nedan.
[img]images/avatar1.gif[/img] images/avatar1.gif
[img]images/avatar2.gif[/img]
images/avatar2.gif
[img]images/avatar3.gif[/img] images/avatar3.gif[img]images/avatar4.jpg[/img]
images/avatar4.jpg
[img]images/avatar5.jpg[/img] images/avatar5.jpg[img]images/avatar6.gif[/img]
images/avatar6.gif
<font face="verdana">
</font></p>
</td>
</tr>
<tr>
<td height='28' align="right"></td>
<td><font face='verdana'><span class="stil2">Profil Beskrivning:</span></font></td>
</tr>
<tr>
<tr>
<td height='28' align="right" valign="top"><font face='verdana'><span class="stil2"></span></font></td>
<td><font size='2' face='verdana'>
<textarea name="quote" cols="80" rows="20"><?= $user_class->desc2 ?>
</textarea>
</font></td>
</tr>
<td></td>
<td><font size='2' face='verdana'>
<input type='submit' name='submit' value='Spara'>
</font></td>
</tr>
</table>
</form>
<?
include 'footer.php';
?>
|