error_reporting(0); session_start(); session_cache_limiter('none'); require_once("admin/inc/baza.inc.php"); //polaczenie z baza require_once("admin/inc/funkcje.inc.php"); //funkcje require_once("admin/inc/menu.inc.php"); //menu require_once("bip.inc.php"); //menu $lista_zabr = array('delete', 'update', 'insert', 'create', 'alter', 'index', 'drop', 'execute', 'shutdown', 'show databases', 'lock tables', 'replication client', 'replication slave', 'create user'); $sqlinj = false; foreach ($_POST as $s_keys=>$s_vals) { foreach ($lista_zabr as &$z_vals) { $s_vals = mb_strtolower($s_vals,'UTF-8'); if (strpos($s_vals,$z_vals)) { $sqlinj=true; } } } foreach ($_GET as $s_keys=>$s_vals) { foreach ($lista_zabr as &$z_vals) { $s_vals = mb_strtolower($s_vals,'UTF-8'); if (strpos($s_vals,$z_vals)) { $sqlinj=true; } } } if ($sqlinj) { echo 'Nie ze mna te numery! Próbuj czegos innego!'; } else { if (!empty($_GET['k']) || !empty($_GET['l'])) { $_SESSION['k'] = $_GET['k']; // kategori $_SESSION['p'] = $_GET['p']; // podkategorie $_SESSION['l'] = $_GET['l']; // languages $_SESSION['a'] = $_GET['a']; // art $_SESSION['od'] = $_GET['od']; //do ile do ile $_SESSION['po'] = $_GET['po']; // po ile wyswietlamy??? } else { $_SESSION['k'] = $_GET['k']; // kategoria $_SESSION['id'] = $_GET['id']; // kategoria $_SESSION['p'] = $_GET['p']; // podkategorie $_SESSION['l'] = $_GET['l']; // languages $_SESSION['k'] = ''; // jezeli nie ma nicz w GET to ładuje to $_SESSION['p'] = ''; $_SESSION['l'] = 'pl'; $_SESSION['a'] = $_GET['a']; // art $_SESSION['od'] = $_GET['od']; //do ile do ile $_SESSION['po'] = $_GET['po']; // po ile wyswietlamy??? } $p = $_SESSION['p']; $k = $_SESSION['k']; $od = $_SESSION['od']; $po = $_SESSION['po']; $a = $_SESSION['a']; $l = $_SESSION['l']; $akt = ($_GET['akt']) ? $_GET['akt'] : 1; //zapytanie key desc i title if(empty($od)) $od=0; if(empty($po)) $po=5; //zapytanie o elemnety na stronie głownej $wynik = mysql_query("select nazwa, tresc from elementy where lang='$l'") or die ("zle pytanie o tresc elementu"); $elementy = array(); //tworze tablice while ($rekord = mysql_fetch_array ($wynik)) { $elementy[] = $rekord; } ?>