| 17 |
exit(); |
exit(); |
| 18 |
} |
} |
| 19 |
|
|
| 20 |
$username=htmlspecialchars(trim($_POST["username"]), ENT_COMPAT | ENT_HTML401, 'UTF-8'); |
$username=trim($_POST["username"]); |
|
$username=addslashes($username); |
|
| 21 |
|
|
| 22 |
if (!preg_match("/^[A-Za-z]{5,12}$/",$username)) |
if (!preg_match("/^[A-Za-z]{5,12}$/",$username)) |
| 23 |
{ |
{ |
| 32 |
|
|
| 33 |
$db_conn=include "./db_open.inc.php"; |
$db_conn=include "./db_open.inc.php"; |
| 34 |
|
|
| 35 |
$rs=mysql_query("select UID from user_list where username='$username' limit 1"); |
$rs=mysql_query("select UID from user_list where username='" . |
| 36 |
|
mysqli_real_escape_string($db_conn, $username) . "' limit 1"); |
| 37 |
if (mysql_num_rows($rs)>0) |
if (mysql_num_rows($rs)>0) |
| 38 |
{ |
{ |
| 39 |
error_msg ("用户名已存在!", true); |
error_msg ("用户名已存在!", true); |
| 41 |
} |
} |
| 42 |
mysql_free_result($rs); |
mysql_free_result($rs); |
| 43 |
|
|
| 44 |
mysql_query("update user_list set username='$username'". |
mysql_query("update user_list set username='" . |
| 45 |
|
mysqli_real_escape_string($db_conn, $username) . "'". |
| 46 |
" where UID=".$_SESSION["BBS_uid"]) |
" where UID=".$_SESSION["BBS_uid"]) |
| 47 |
or die("Update error!"); |
or die("Update error!"); |
| 48 |
|
|