31.01.2014, 01:10
Quote:
Looks like SQL injection. Print out the entire query. Make sure you escape the input string (mysql_real_escape_string() IIRC).
|
pawn Код:
new safestring[129] //129 is max input right? o_O
mysql_real_escape_string(inputtext,safestring);
pawn Код:
new query[124];
format(query,sizeof(query),"UPDATE `accounts` SET `Admin`='%d' WHERE `name`='%s'",safestring,Name[playerid]);
mysql_query(query);