$condition = ' AND username LIKE "' . $FORM['username'] . '" ';
$sql = $db->getRecFrmQry("SELECT * FROM " . DB_TBLPREFIX . "_mbrs WHERE 1 " . $condition . "");
if (count($sql) > 0 || $isunexist) {
// do nothing
$_SESSION['dotoaster'] = "toastr.warning('Record not added <strong>Username exist!</strong>', 'Warning');";
} elseif (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
$_SESSION['dotoaster'] = "toastr.error('Record not added <strong>Invalid input format!</strong>', 'Error');";
Что я делаю не так?1) Не используете подготовленные выражения в SQL
$_SESSION['dotoaster'] = "toastr.error('".
$LANG['n_error'].
" <strong>Invalid input format!</strong>', 'Error');";