<?php
if(isset($_GET['change']) AND $number = $_GET['change'] AND ctype_digit($number)){}
else {
$number = "10";
}
?>
<?php
if($_GET['act'] == 'getNum') {
if(isset($_GET['change']) AND $number = $_GET['change'] AND ctype_digit($number)){}
else {
$number = "10";
}
$getUsers = sprintf("SELECT id, username, answer_point, howto_point
FROM login
LIMIT %d", $number);
$showUsers = mysql_query($getUsers) or die("Users not showing because: " . mysql_error());
while($u = mysql_fetch_array($showUsers)) {
if(!empty($u['answer_point']) AND !empty($u['howto_point'])) {
$points = $u['answer_point'] + $u['howto_point'];
echo " <div class='performer'>
<div class='user'>{$u['username']}</div>
<div class='points'>$points</div>
</div>
";
}
}
}
?>
$number = $_GET['change'];
with this
if(($number = $_GET['change']) AND $number=="10") $number = "10";