if ((eregi("[^a-zA-Z0-9_-]", $oldpwd)) || (eregi("[^a-zA-Z0-9_-]", $login)) || (eregi("[^0-9_-]", $vitality)) || (eregi("[^0-9_-]", $strength)) || (eregi("[^0-9_-]", $energy)) || (eregi("[^0-9_-]", $dexterity)))
{
echo("SQL Injection Detected");
exit();
}
$account_id = stripslashes($_SESSION['user']);
$account_id = clean_var($account_id);
require("config.php");
$account_id = stripslashes($_SESSION['user']);
$account_id = clean_var($account_id);
$character = mssql_query("SELECT * FROM accountcharacter WHERE ID='$account_id'");
$char = mssql_fetch_array($character);
function skills_clear() {
if ((isset($_SESSION['pass'])) && (isset($_SESSION['user']))); {
$login = stripslashes($_SESSION['user']);
$char = stripslashes($_POST['chars']);
$char = str_replace("'" , "", $char);
$char = str_replace(";" , "", $char);
$online_check = mssql_query("SELECT * FROM MEMB_STAT WHERE memb___id='$login'");
$online_checked = mssql_fetch_array($online_check);
if (empty($char)) { echo "<table class='unsuccess' width='350' border='0' cellpadding='0' cellspacing='0' align='center'><tr><td class='left'>Please Select Character!</td></tr></table><br />"; $error=1; }
if ($online_checked['ConnectStat'] != 0){ echo "<table class='unsuccess' width='350' border='0' cellpadding='0' cellspacing='0' align='center'><tr><td class='left'>Account is online, must be logged off!</td></tr></table><br />"; $error=1; }
if($error !=1) {
$clear_skills = "UPDATE Character SET [magiclist]=CONVERT(varbinary(180), null) WHERE Name='$char'";
$skills_results= mssql_query($clear_skills);
echo "<table class='success' width='350' border='0' cellpadding='0' cellspacing='0' align='center'><tr><td class='left'>Magic List of <font color='#75484F'>$char</font> has been successfully cleared!</td></tr></table><br />";
}
}
}
if (isset($_POST["skillsclear"])) {skills_clear();}
?>