create('invite'); $id = isset($_GET['id']) ? 0 + $_GET["id"] : $CURUSER['id']; $type = unesc($_GET["type"]); if ($CURUSER[id] != $id && get_user_class() < UC_ADMINISTRATOR && !is_valid_id($id)) stderr("Sorry","Permission Denied!"); stdhead("Invites"); $res = sql_query("SELECT invites FROM users WHERE id = ".mysql_real_escape_string($id)) or sqlerr(); $inv = mysql_fetch_assoc($res); if ($inv["invites"] != 1){ $_s = "s"; } else { $_s = ""; } if ($type == 'new'){ if ($CURUSER[invites] <= 0) { stdmsg("Sorry","You have no invites left!"); stdfoot(); die; } $sent = htmlspecialchars($_GET['sent']); if ($sent == 1) $msg = "The invite code has been sent!"; print("