$g = _string(_num($_POST['g'])); $s = _string(_num($_POST['s'])); if(!empty($g) OR !empty($s)) { if( !empty($g) and $user['g'] >= $g and $g>'0' and $g<'100000') { mysql_query('UPDATE `clans` SET `g` = `g` + '.$g.' WHERE `id` = "'.$clan['id'].'"'); mysql_query('UPDATE `users` SET `g` = `g` - '.$g.' WHERE `id` = "'.$user['id'].'"'); } if(!empty($s) and $user['s'] >= $s and $s>'0' and $s<'100000') { mysql_query('UPDATE `clans` SET `s` = `s` + '.$s.' WHERE `id` = "'.$clan['id'].'"'); mysql_query('UPDATE `users` SET `s` = `s` - '.$s.' WHERE `id` = "'.$user['id'].'"'); } header('location: /clan/money/'); }