<?
$sql = "SELECT * FROM `web_accounts` WHERE username='" . htmlentities($_GET['user']) .
"' AND validation_code='" . htmlentities($_GET['code']) . "';";
$suser = $db->query_first($sql);
if (!isset($suser['username']))
{
$content = $smarty->fetch('error_activate.tpl');
} else
{
$sql = "INSERT INTO `accounts` ( `login` , `password` , `lastactive` , `access_level` , `lastIP` , `lastServer` )
VALUES (
'" . $suser['username'] . "', '" . $suser['password'] . "', 0, '0', '" . $_SERVER['REMOTE_ADDR'] .
"', '1'
);";
$db->query($sql);
if (!$db->error)
{
$content = $smarty->fetch('success_activate.tpl');
$db->query("UPDATE `web_accounts` SET `validation_code` = '" . md5("liposuction" .
time()) . "' WHERE `username` ='" . $suser['username'] . "' LIMIT 1 ;");
} else
{
$content = $smarty->fetch('error_activate.tpl');
}
}
?>