<?
/*
PTK - DFLabs
Copyright (C) 2008 - DFLabs srl - All rights reserved
hide@address.com
*/
include("check_session.php");
include("check_session_image.php");
include("../config/config.inc.php");
include ("sanitize.php");
include ("loggerClass.php");
include ("../config/conf.php");
$conn = mysql_connect($db_host, $db_user, $db_password)
or die ("Error connecting to database");
mysql_select_db($db_name);
session_start();
$id = sanitize($_GET['id'],INT);
$description = mysql_real_escape_string(sanitize(RemoveXSS($_GET['description']),PARANOID));
$tags = mysql_real_escape_string(sanitize_tag(RemoveXSS($_GET['tags'])));
$user = mysql_real_escape_string(sanitize(RemoveXSS($_SESSION['user']),PARANOID));
if ($user == 'admin'){
$query=mysql_query("UPDATE bookmarks SET description='$description', tags='$tags' WHERE id=$id");
}else{
$query=mysql_query("UPDATE bookmarks SET description='$description', tags='$tags' WHERE id=$id AND user='$user'");
}
mysql_close();
new Log($_SESSION['ip'], $_SESSION['user'], 'Bookmark updated');
?>