if($action == "add"){ if(isset($_POST['send'])) { if($_FILES['avatar_file']['tmp_name'] == "none") eval ("\$avatar_error = \"".gettemplate("avatar_error")."\";"); else { $avatar_extension = strtolower(substr(strrchr($_FILES['avatar_file']['name'],"."),1)); $avatar_name = substr($_FILES['avatar_file']['name'],0,(intval(strlen($avatar_extension))+1)*-1); $db->query("INSERT INTO bb".$n."_avatars (avatarid,avatarname,avatarextension,groupid,needposts,userid) VALUES (NULL,'".addslashes($avatar_name)."', '".addslashes($avatar_extension)."','".$_POST['groupid']."', '".$_POST['needposts']."', '0')"); $avatarid = $db->insert_id(); if(move_uploaded_file($_FILES['avatar_file']['tmp_name'], "../images/avatars/avatar-".$avatarid.".".$avatar_extension."")){ chmod("../images/avatars/avatar-".$avatarid.".".$avatar_extension,0644); $imagesize = @getimagesize("../images/avatars/avatar-".$avatarid.".".$avatar_extension); $width = $imagesize[0]; $height = $imagesize[1]; $db->unbuffered_query("UPDATE bb".$n."_avatars SET width='$width', height='$height' WHERE avatarid='$avatarid'",1); header("Location: avatar.php?action=view&sid=$session[hash]"); exit(); } else { $db->query("DELETE FROM bb".$n."_avatars WHERE avatarid = '".$avatarid."'"); eval ("\$avatar_error = \"".gettemplate("avatar_error")."\";"); } } } $result = $db->query("SELECT groupid, title, canuseavatar, allowedavatarextensions, maxavatarwidth, maxavatarheight, maxavatarsize FROM bb".$n."_groups WHERE default_group <> 1"); while($row = $db->fetch_array($result)) $avatar_groupsbit .= makeoption($row['groupid'],$row['title'],"",0); eval("print(\"".gettemplate("avatar_add")."\");"); }