<?php
if(secure($_SESSION['user']) == true)
{
$account = secure($_SESSION['user']);
$exchangereset = '500'; // Credits from exchange 1 Reset
if(isset($_POST['exchange']))
{
$account = secure($_SESSION['user']);
$character = secure($_POST['character']);
$resets = secure($_POST['resets']);
check_inject();
$querychar = mssql_query("Select resets from character where name='$character'");
$char = mssql_fetch_row($querychar);
$newresets = $char[0] - $resets;
if($newresets < 0) { echo"<br><font color='red'>Not enought resets!</font><br>"; $error = 1; }
elseif($resets < 0) { echo"<br><font color='red'>Error! You Can't put - numbers!</font><br>"; $error = 1; }
elseif($error != 1) {
$credits = $resets * $exchangereset;
echo"<br><font color='green'>You exchange $resets reset(s) for $credits credits</font><br>";
$a = mssql_query("Update Character set resets='$newresets' where name='$character'");
$b = mssql_query("Update MEMB_CREDITS set credits = credits+$credits WHERE memb___id='$account'");
}
}
$query = mssql_query("Select name,resets from character where AccountID='$account'");
echo"
<form action='' name='' method='POST'>
<select id='character' name='character'><optgroup label='Select a character'>
";
for($i=0;$i < mssql_num_rows($query);++$i)
{
$row = mssql_fetch_row($query);
echo"
<option value='$row[0]'>$row[0] [$row[1]]</option>
";
}
echo"</select>
<br><input type='text' size='25' id='resets' name='resets' />
<br><input type='submit' maxlength='2' value='exchange' name='exchange'>
</form>
<br>1 Reset = $exchangereset Credits!
";
}
else
{
echo "Please First Login";
}
?>