diff --git a/src/act.php b/src/act.php index f404db9..20c872c 100644 --- a/src/act.php +++ b/src/act.php @@ -108,7 +108,7 @@ switch($_POST['act']){ //check name $rs=mysqli_query($lnMysql, "SELECT 1 FROM bots - WHERE name='".mysqli_real_escape_string($lnMysql,html_entities($_POST['botName']))."' + WHERE name='".mysqli_real_escape_string($lnMysql,htmlentities($_POST['botName']))."' AND game='".mysqli_real_escape_string($lnMysql,$_POST['botGame'])."' AND id <> '".mysqli_real_escape_string($lnMysql,$_POST['botId'])."'" );