/*
___________________________________________________
project : asn guestbook version 1.5
file : guestbook.php
author : asn - webmaster@tourdebali.com
date : 21st may 2002
note : copyright 2002 by asn
___________________________________________________
*/
include("config.php");
include("library.php");
include("header.php");
if (!isset($act)) {
$act = '';
}
switch ($act) {
//======================================================================================================
case "":
include("form.html");
$query = mysql_query("SELECT * FROM $tab WHERE accepted = '1' ORDER BY id ASC");
$all_record = mysql_num_rows($query);
if (!isset($page) || $page == "") $page = 1;
// >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
if ($all_record <= $itemperpage) {$pagenumber = 1;} else
{
if (($all_record % $itemperpage) == 0) {$pagenumber = intval($all_record/$itemperpage);} else
{$pagenumber = intval($all_record/$itemperpage) + 1;}
}
if ($pagenumber == 1) {
$start = 1;
$end = $all_record;
$looping = $all_record; } else {
if (($all_record % $itemperpage) == 0) {
$sisa = $itemperpage;
} else {
$sisa = $all_record % $itemperpage; }
if ($page == $pagenumber) {
$start = 1;
$end = $sisa;
$looping = $sisa; } else {
$end = (($pagenumber - $page) * $itemperpage) + $sisa;
$start = $end - $itemperpage + 1;
$looping = $itemperpage;}
}
// >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
navigation($pagenumber, $page);
for ($i=1; $i<=$looping; $i++) {
$counter = $end - $i;
$seekrecord = mysql_data_seek($query, $counter);
$data = mysql_fetch_row($query);
$datenow = date("d M Y", $data[0]);
$nomor = $counter + 1;
echo "

| [$nomor]
$datenow, $data[1] [" . substr($data[4],0,1) . "]";
echo "
escribio: |
";
if ($data[2] <> "") echo " ";
if ($data[3] <> "") echo " ";
if ($smile == 1) $data[5] = smile($data[5]);
if ($auto_url == 1) $data[5] = auto_url($data[5]);
if ($smile == 1) $data[6] = smile($data[6]);
if ($auto_url == 1) $data[6] = auto_url($data[6]);
echo "
|
".ereg_replace("\n"," ",$data[5]). "
";
if ($data[6] <> "") {
echo "
$reply_subject $data[6]";
}
echo "
|
";
}
navigation($pagenumber, $page);
break;
//======================================================================================================
case "doadd":
$vdate = time();
$_SESSION['vname'] = $vname = $_POST['vname'];
$_SESSION['vemail'] = $vemail = $_POST['vemail'];
$_SESSION['vwebsite'] = $vwebsite = $_POST['vwebsite'];
$_SESSION['vgender'] = $vgender = $_POST['vgender'];
$_SESSION['vcomment'] = $vcomment = $_POST['vcomment'];
if (($vname =="") or ($vemail =="") or ($vcomment =="")) erro("Algunos campos no han sido completados. Por favor reviselos!");
if (!ereg("([[:alnum:]\.\-]+)(\@[[:alnum:]\.\-]+\.+)", $vemail)) erro("Direccion de Email Invalida!");
if (trim($vwebsite) == "http://") $vwebsite = "";
$vname = str_replace("<","",$vname);
$vname = str_replace(">","",$vname);
$vemail = str_replace("<","",$vemail);
$vemail = str_replace(">","",$vemail);
$vwebsite = str_replace("<","",$vwebsite);
$vwebsite = str_replace(">","",$vwebsite);
$vgender = str_replace("<","",$vgender);
$vgender = str_replace(">","",$vgender);
$test_comment = explode(" ",$vcomment);
$jmltest = count($test_comment);
$_SESSION['vname'] = $vname;
$_SESSION['vemail'] = $vemail;
$_SESSION['vwebsite'] = $vwebsite;
$_SESSION['vgender'] = $vgender;
$_SESSION['vcomment'] = $vcomment;
for ($t=0; $t<$jmltest; $t++) {
if (strlen(trim($test_comment[$t])) > 60) {
erro("Maximum character for one word is 60!");
}
}
require_once('securimage/securimage.php');
$img = new Securimage();
$valid = $img->check($_POST['code']);
if(!$valid) {
erro("El código de Seguridad es incorrecto!");
}
$vcomment = str_replace("<","<",$vcomment);
$vcomment = str_replace(">",">",$vcomment);
//$vcomment = str_replace("\n","
",$vcomment);
$shit_words = array('casino','cash','refinance','refinancing',
'viagra','nice site','money','free','porn','online',
'Bush','Sveta','ZZzz','incest','Britney','woman','Papay','free','coach','Helga','sexual','lesbian');
$insert = true;
foreach ($shit_words as $word) {
if(strstr($vname,$word)) {
$insert = false;
break;
}
if(strstr($vemail,$word)) {
$insert = false;
break;
}
if(strstr($vwebsite,$word)) {
$insert = false;
break;
}
if(strstr($vcomment,$word)) {
$insert = false;
break;
}
}
if ($insert) {
$doit = mysql_query("INSERT INTO $tab
(date ,name , email ,website ,gender ,comment)
VALUES('$vdate','$vname','$vemail','$vwebsite','$vgender','$vcomment')");
$_SESSION['vname'] = '';
$_SESSION['vemail'] = '';
$_SESSION['vwebsite'] = '';
$_SESSION['vgender'] = '';
$_SESSION['vcomment'] = '';
}
echo "
|
Su comentario ha sido grabado.
Si quiere ver todos los comentarios realizados haga click aqui
Tan pronto como nos sea posible le contestaremos
Muchas Gracias...
|
";
if ($notify == 1) {
$header = "Content-type: text/html\nFrom: " . $mail_from ;
mail($admin_email, $mail_subject, $vcomment, $header);
}
}
include("footer.php");
?>