require "include/bittorrent.php"; dbconn(); loggedinorreturn(); if (get_user_class() < UC_MODERATOR) stderr( _("Error"),_("Permission denied.")); $action = htmlspecialchars($_GET["action"]); $pollid = (int) $_GET["pollid"]; if ($action == "edit") { if (!is_valid_id($pollid)) stderr( _("Error"),"Invalid ID."); $res = do_mysql_query("SELECT * FROM polls WHERE id = $pollid") or sqlerr(__FILE__, __LINE__); if (mysql_num_rows($res) == 0) stderr( _("Error"), _("No poll found with ID.") ); $poll = mysql_fetch_assoc($res); } if ($_SERVER["REQUEST_METHOD"] == "POST") { $pollid = $_POST["pollid"]; $question = $_POST["question"]; $option0 = $_POST["option0"]; $option1 = $_POST["option1"]; $option2 = $_POST["option2"]; $option3 = $_POST["option3"]; $option4 = $_POST["option4"]; $option5 = $_POST["option5"]; $option6 = $_POST["option6"]; $option7 = $_POST["option7"]; $option8 = $_POST["option8"]; $option9 = $_POST["option9"]; $option10 = $_POST["option10"]; $option11 = $_POST["option11"]; $option12 = $_POST["option12"]; $option13 = $_POST["option13"]; $option14 = $_POST["option14"]; $option15 = $_POST["option15"]; $option16 = $_POST["option16"]; $option17 = $_POST["option17"]; $option18 = $_POST["option18"]; $option19 = $_POST["option19"]; $sort = $_POST["sort"]; $returnto = htmlspecialchars($_POST["returnto"]); if (!$question || !$option0 || !$option1) stderr( _("Error"), _("Missing form data!") ); if ($pollid) do_mysql_query("UPDATE polls SET " . "question = " . sqlesc($question) . ", " . "option0 = " . sqlesc($option0) . ", " . "option1 = " . sqlesc($option1) . ", " . "option2 = " . sqlesc($option2) . ", " . "option3 = " . sqlesc($option3) . ", " . "option4 = " . sqlesc($option4) . ", " . "option5 = " . sqlesc($option5) . ", " . "option6 = " . sqlesc($option6) . ", " . "option7 = " . sqlesc($option7) . ", " . "option8 = " . sqlesc($option8) . ", " . "option9 = " . sqlesc($option9) . ", " . "option10 = " . sqlesc($option10) . ", " . "option11 = " . sqlesc($option11) . ", " . "option12 = " . sqlesc($option12) . ", " . "option13 = " . sqlesc($option13) . ", " . "option14 = " . sqlesc($option14) . ", " . "option15 = " . sqlesc($option15) . ", " . "option16 = " . sqlesc($option16) . ", " . "option17 = " . sqlesc($option17) . ", " . "option18 = " . sqlesc($option18) . ", " . "option19 = " . sqlesc($option19) . ", " . "sort = " . sqlesc($sort) . " " . "WHERE id = $pollid") or sqlerr(__FILE__, __LINE__); else do_mysql_query("INSERT INTO polls VALUES(0" . ", NOW() " . ", " . sqlesc($question) . ", " . sqlesc($option0) . ", " . sqlesc($option1) . ", " . sqlesc($option2) . ", " . sqlesc($option3) . ", " . sqlesc($option4) . ", " . sqlesc($option5) . ", " . sqlesc($option6) . ", " . sqlesc($option7) . ", " . sqlesc($option8) . ", " . sqlesc($option9) . ", " . sqlesc($option10) . ", " . sqlesc($option11) . ", " . sqlesc($option12) . ", " . sqlesc($option13) . ", " . sqlesc($option14) . ", " . sqlesc($option15) . ", " . sqlesc($option16) . ", " . sqlesc($option17) . ", " . sqlesc($option18) . ", " . sqlesc($option19) . ", " . sqlesc($sort) . ")") or sqlerr(__FILE__, __LINE__); if ($returnto == "main") header("Location: ".$GLOBALS['DEFAULTBASEURL']); elseif ($pollid) header("Location: polls.php#$pollid"); else header("Location: ".$GLOBALS['DEFAULTBASEURL']); die; } stdhead(); if ($pollid) print("
Note: The current poll (" . $arr["question"] . ") is only $t old.
"); } } print("* required
> > stdfoot(); ?>