HEX
Server: Apache
System: Linux msm5694.mjhst.com 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: camjab_ssh (1000)
PHP: 5.3.29
Disabled: NONE
Upload Files
File: /home/httpd/html/baretube.com.new/includes/ajax.approve_friend.php
<?php 
    include('../mb.php');
    if(!$_SESSION[userid]) {
	header("Location: $basehttp");
	exit();
    } 

    $id = mysqli_real_escape_string($dbconn,$_GET[id]);
    if(!is_numeric($id)) { exit(); } 

    if(is_numeric($_GET[approved])) {
	$approved=1;
    } 
    
    $sql="SELECT user FROM friends WHERE record_num = '$id' AND approved = 0 AND `friend` = '$_SESSION[userid]'";		
    $drow = dbQuery($sql,false);	
    if($drow){		
	$user=$drow[0]['user'];
	dbQuery("UPDATE friends SET  approved = 1 WHERE record_num = '$id'",false); 
        
	$time = date('Y-m-d H:i:s',time());
	dbQuery("INSERT INTO friends (`user` , `friend` ,`approved` ,`date_added`) VALUES('$_SESSION[userid]','$user','1','".$time."')");
        
        sendEmail('friend-request-confirmation',$user);
    }	
    exit();