i m trying to stop a head admin that he cannot able to moderate owner profile but i cant find out my mistake.
anybody can fix my error. thnks...............
anybody can fix my error. thnks...............
PHP Code:
else if($action=="user")
{
$who = $_GET["who"];
echo "<head>";
echo "<title>Head Admin Tools</title>";
echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/$theme[0]\">";
echo "</head>";
echo "<body>";
echo "<p align=\"center\">";
$uid = getuid_sid($sid);
$perm = mysql_fetch_array(mysql_query("SELECT perm FROM ibwf_users WHERE id='".$uid."'"));
$trgtperm = mysql_fetch_array(mysql_query("SELECT perm FROM ibwf_users WHERE name='".$user."'"));
if($trgtperm>$perm){
echo "<b><img src=\"../images/notok.gif\" alt=\"x\"/><br/>Error!!!<br/>Permission Denied...</b><br/>";
echo "<br/>U Cannot Moderate $user<br/>";
echo "<a href=\"index.php?action=main\"><img src=\"../images/home.gif\" alt=\"\"/>Home</a>";
echo "</p>";
}else{
$unick = getnick_uid($who);
echo "<b>Moderating $unick</b>";
echo "</p>";
echo "<p align=\"center\">";
echo "<a href=\"admincp.php?action=plsopt&who=$who\">Plusses</a><br/>";
$noi = mysql_fetch_array(mysql_query("SELECT count(*) FROM ibwf_users WHERE validated='0' AND id='".$who."'"));
if($noi[0]==1)
{
echo "<a href=\"headadmnproc.php?action=validate&who=$who\">Validate</a><br/>";
}
echo "<a href=\"headadmnproc.php?action=boot&who=$who\">Boot</a><br/>";
if(!istrashed($who))
{
echo "<a href=\"headadmincp.php?action=trash&who=$who\">Trash</a><br/>";
}else{
echo "<a href=\"headadmnproc.php?action=untr&who=$who\">Untrash</a><br/>";
}
if(!isbanned($who))
{
echo "<a href=\"headadmincp.php?action=ban&who=$who\">Ban</a><br/>";
echo "<a href=\"headadmincp.php?action=ipban&who=$who\">Ip-ban</a><br/>";
}else{
echo "<a href=\"headadmnproc.php?action=unbn&who=$who\">Unban</a><br/>";
}
if(!isshield($who))
{
echo "<a href=\"headadmnproc.php?action=shld&who=$who\">Shield</a><br/>";
}else{
echo "<a href=\"headadmnproc.php?action=ushld&who=$who\">Unshield</a><br/>";
}
echo "<form action=\"headadmincp.php?action=acui\" method=\"post\">";
echo "<input type=\"hidden\" name=\"unick\" value=\"$unick\"/>";
echo "<input type=\"Submit\" value=\"Edit User\" Name=\"Submit\"/></form>";
echo "<b>0 </b><a accesskey=\"0\" href=\"index.php?action=main\"><img src=\"../images/home.gif\" alt=\"\"/>Home</a>";
echo "</p></body>";
}}
Comment