ob_start("ob_gzhandler"); ?> include("../include/dbfunc.inc"); ?> include ("../include/common.inc"); ?> include ("../include/common_enc.inc"); ?> $reval = SQL_Injection($_POST,$REMOTE_ADDR);?> $active_handler = "off"; ?> $ad_menu = "myflash"; ?> //SQL INJECTION 모니터링 if($reval != "") { openMySql3("ZUZUNZA"); $sql = "insert into sql_log set sqltext='$reval',reg_date=NOW(),IP='$REMOTE_ADDR'"; @mysql_query($sql); die(); } ?> include ("../include/dirkpgselector.inc"); ?> include "../include/CheckAdult.inc"; ?> if(is_numeric($game_id)) { } else { die(); } ?> openMySql2("ZUZUNZA"); ?> $game_id = str_replace("from=yahoo","",$game_id); ?> $game_id = str_replace("'","''",$game_id); ?> $game_id = mysql_real_escape_string($game_id); $category = mysql_real_escape_string($category); $order = mysql_real_escape_string($order); $searchword = mysql_real_escape_string($searchword); $mygameroom = mysql_real_escape_string($mygameroom); $cp = mysql_real_escape_string($cp); $p = mysql_real_escape_string($p); $tm1 = mysql_real_escape_string($tm1); ?> if($tm1 == "") $tm1 = 1; ?> if($game_id == "") $game_id = 1; ?> $game_category = array("선택","플래시완성작품","페이퍼 일반","페이퍼 인간화","버튼애니","붓틀액션","간단작품","모집/과제","의견/기타");?> if($game_id=='422739') { $Query = "select * from flashgame_myflash_honor where game_id='$game_id'"; } else { //$Query = "select * from flashgame_myflash where uid='$game_id'"; $Query = sprintf("select * from flashgame_myflash where uid=%s",mysql_real_escape_string($game_id)); } $res = mysql_query($Query) or die(); //게임 정보 가져오기 $row = mysql_fetch_array($res); if($row[block_num]>=2) { echo ("