| 341 |
|
|
| 342 |
if($row = mysqli_fetch_array($rs)) |
if($row = mysqli_fetch_array($rs)) |
| 343 |
{ |
{ |
| 344 |
$nickname = mysqli_escape_string($db_conn, $row["nickname"]); // Nickname may include special characters |
$nickname = $row["nickname"]; |
| 345 |
$exp = $row["exp"]; |
$exp = $row["exp"]; |
| 346 |
} |
} |
| 347 |
mysqli_free_result($rs); |
mysqli_free_result($rs); |
| 624 |
$sql = "UPDATE bbs SET reply_count = reply_count + 1, |
$sql = "UPDATE bbs SET reply_count = reply_count + 1, |
| 625 |
last_reply_dt = NOW(), last_reply_UID=" . $_SESSION["BBS_uid"] . |
last_reply_dt = NOW(), last_reply_UID=" . $_SESSION["BBS_uid"] . |
| 626 |
", last_reply_username = '" . $_SESSION["BBS_username"] . |
", last_reply_username = '" . $_SESSION["BBS_username"] . |
| 627 |
"', last_reply_nickname = '$nickname' WHERE Aid = $tid"; |
"', last_reply_nickname = '" . mysqli_real_escape_string($db_conn, $nickname) . |
| 628 |
|
"' WHERE Aid = $tid"; |
| 629 |
|
|
| 630 |
$rs = mysqli_query($db_conn, $sql); |
$rs = mysqli_query($db_conn, $sql); |
| 631 |
if ($rs == false) |
if ($rs == false) |