include("../config/conn.php"); include("../config/function.php"); sesCheck(); $sqluser="select * from yjcode_user where uid='".$_SESSION[SHOPUSER]."' and shopzt=2";mysql_query("SET NAMES 'GBK'");$resuser=mysql_query($sqluser); if(!$rowuser=mysql_fetch_array($resuser)){php_toheader("openshop3.php");} $userid=$rowuser[id]; $bh=$_GET[bh]; while0("*","yjcode_server where bh='".$bh."' and userid=".$userid);if(!$row=mysql_fetch_array($res)){php_toheader("serverlist.php");} if($_GET[control]=="add"){ $sj=getsj(); $tyid=preg_split("/xcf/",sqlzhuru($_POST[d1])); if(panduan("bh","yjcode_tp where bh='".$bh."'")==1){$iftp=1;}else{$iftp=0;} $txt=sqlzhuru1($_POST[content]); $wdes=sqlzhuru($_POST[twdes]);if(empty($wdes)){$wdes=strgb2312(strip_tags($txt),0,220);} $tit=sqlzhuru($_POST[ttit]); $wkey=sqlzhuru($_POST[twkey]);if(empty($wkey)){$wkey=$tit;} $money1=sqlzhuru($_POST[tmoney1]);if(!is_numeric($money1)){$money1=0;} if($rowcontrol[ifserver]=="on"){$nzt=0;}else{$nzt=1;} updatetable("yjcode_server"," mybh='".sqlzhuru($_POST[tmybh])."', lastsj='".$sj."', uip='".getuip()."', ty1id=".$tyid[0].", ty2id=".$tyid[1].", tit='".$tit."', txt='".$txt."', wdes='".$wdes."', wkey='".$wkey."', money1=".$money1.", iftp=".$iftp.", zt=".$nzt." where bh='".$bh."' and userid=".$row[userid]); php_toheader("server.php?t=suc&bh=".$bh); } ?>