Файл: profile.php
Строк: 220
<?php
ini_set('display_errors', 'off');
header ("Content-type: text/html; charset=utf-8");
header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT");
header("Cache-Control: no-cache, must-relative");
print '<?xml version="1.0" encoding="UTF-8"?>';
print "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8">";
print "<title>Профиль</title><link rel="StyleSheet" type="text/css" href="style/0".$s.".css"></head><body>";
include "./ini.php";
print "<div style="text-align: center">
<div class="contur_rek"><div class="header_rek">Смена инфы</div></div></div>";
print "<div class="contur"><div class="header">";
mysql_query ("select * from bannedib WHERE ci='$ci' AND (ip = '".getenv(REMOTE_ADDR)."')and(browser = '".getenv(HTTP_USER_AGENT)."')");
if(mysql_affected_rows()!=0){include "b.php";}
$login = autorize();
//защита от вставки тегов, во избежание искажения страницы:
// <
$login['name'] = str_replace("<","",$login['name']);
$login['live'] = str_replace("<","",$login['live']);
$login['mobile'] = str_replace("<","",$login['mobile']);
$login['operator'] = str_replace("<","",$login['operator']);
$login['email'] = str_replace("<","",$login['email']);
$login['about'] = str_replace("<","",$login['about']);
$data['photo'] = str_replace("<","",$data['photo']);
$login['wapsite'] = str_replace("<","",$login['wapsite']);
$login['website'] = str_replace("<","",$login['website']);
// *
$login['name'] = str_replace("*","",$login['name']);
$login['live'] = str_replace("*","",$login['live']);
$login['mobile'] = str_replace("*","",$login['mobile']);
$login['operator'] = str_replace("*","",$login['operator']);
$login['email'] = str_replace("*","",$login['email']);
$login['about'] = str_replace("*","",$login['about']);
$data['photo'] = str_replace("*","",$data['photo']);
$login['wapsite'] = str_replace("*","",$login['wapsite']);
$login['website'] = str_replace("*","",$login['website']);
// =
$login['name'] = str_replace("=","",$login['name']);
$login['live'] = str_replace("=","",$login['live']);
$login['mobile'] = str_replace("=","",$login['mobile']);
$login['operator'] = str_replace("=","",$login['operator']);
$login['email'] = str_replace("=","",$login['email']);
$login['about'] = str_replace("=","",$login['about']);
$data['photo'] = str_replace("=","",$data['photo']);
$login['wapsite'] = str_replace("=","",$login['wapsite']);
$login['website'] = str_replace("=","",$login['website']);
// &
$login['name'] = str_replace("&","",$login['name']);
$login['live'] = str_replace("&","",$login['live']);
$login['mobile'] = str_replace("&","",$login['mobile']);
$login['operator'] = str_replace("&","",$login['operator']);
$login['email'] = str_replace("&","",$login['email']);
$login['about'] = str_replace("&","",$login['about']);
$data['photo'] = str_replace("&","",$data['photo']);
$login['wapsite'] = str_replace("&","",$login['wapsite']);
$login['website'] = str_replace("&","",$login['website']);
// $
$login['name'] = str_replace("$","",$login['name']);
$login['live'] = str_replace("$","",$login['live']);
$login['mobile'] = str_replace("$","",$login['mobile']);
$login['operator'] = str_replace("$","",$login['operator']);
$login['email'] = str_replace("$","",$login['email']);
$login['about'] = str_replace("$","",$login['about']);
$data['photo'] = str_replace("$","",$data['photo']);
$login['wapsite'] = str_replace("$","",$login['wapsite']);
$login['website'] = str_replace("$","",$login['website']);
print '<card title="Профиль">'.
'<p align="center">';
if(empty($id))
print "<div class="smain">Логин пуст!</div><br/>";
if($login) {
if(empty($action)) {
print '<div class="smain"><form action="profile.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'" method="post">Имя:<br/>'.
'<input type="text" name="name" value="'.$login['name'].'"/><br/>'.
'Новый пароль:<br/>'.
'<input type="text" name="newpass" value="'.$login['pass'].'"/><br/>'.
'Пол:<br/>'.
'<select name="sex" title="Пол" value="'.$login['sex'].'">'.
'<option value="m">М</option>'.
'<option value="zh">Ж</option></select><br/>'.
'Дата рождения:<br/>'.
'<input size="2" name="bday" maxlength="2" value="'.$login['bday'].'" format="*N"/>-<input size="2" name="bmonth" maxlength="2" value="'.$login['bmonth'].'" format="*N"/>-<input size="4" name="byear" maxlength="4" value="'.$login['byear'].'" format="*N"/><br/>'.
'Место жительства:<br/>'.
'<input type="text" name="live" value="'.$login['live'].'"/><br/>'.
'Модель мобилы:<br/>'.
'<input type="text" name="mobile" value="'.$login['mobile'].'"/><br/>'.
'e-mail:<br/>'.
'<input type="text" name="email" value="'.$login['email'].'"/><br/>'.
'WAP-сайт:<br/>'.
'<input type="text" name="wapurl" value="'.$login['wapsite'].'"/><br/>'.
'WEB-сайт:<br/>'.
'<input type="text" name="weburl" value="'.$login['website'].'"/><br/>'.
'ICQ:<br/>'.
'<input name="icq" value="'.$login['icq'].'" format="*N"/><br/>'.
'Адрес Фото:<br/>'.
'<input type="text" name="foto" maxlength="80" value="'.$login['photo'].'"/><br/>'.
'О себе:<br/>'.
'<input type="text" name="about" value="'.$login['about'].'"/><br/>'.
'<input type="hidden" name="action" value="edit"/><input type="submit" value="Изменить"></form></div></div></div>'.
'<div style="text-align: center">
<div class="contur_rek"><div class="header_rek"><a href="enter.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'">Прихожая</a></div></div></div>';
}
else
{
$newpass=stripslashes(strip_tags(trim(hacs($newpass))));
$name=htmlspecialchars(stripslashes(trim(hacs($name))));
$live=htmlspecialchars(stripslashes(trim(hacs($live))));
$sex=htmlspecialchars(stripslashes(trim(hacs($sex))));
$mobile=htmlspecialchars(stripslashes(trim(hacs($mobile))));
$email=htmlspecialchars(stripslashes(trim(hacs($email))));
$wapurl=htmlspecialchars(stripslashes(trim(hacs($wapurl))));
$icq=htmlspecialchars(stripslashes(trim(hacs($icq))));
$weburl=htmlspecialchars(stripslashes(trim(hacs($weburl))));
$foto=htmlspecialchars(stripslashes(trim(hacs($foto))));
$about=htmlspecialchars(stripslashes(trim(hacs($about))));
//
if(@mysql_query("update `".$px.$utable."` set name='$name',pass='$newpass',sex='$sex',bday='$bday',bmonth='$bmonth',byear='$byear',live='$live',mobile='$mobile',email='$email',wapsite='$wapurl',website='$weburl',icq='$icq',photo='$foto',about='$about' where id='$id' and ci='$ci';"))
print "<div class="smain"><b>Ваш профиль изменен!</b></div><br/>";
print "<div class="smain"><a href="enter.php?s=$s&ci=$ci&id=$id&pass=$newpass">Прихожая</a></div>";
}
if(!$action)
print "";
}
else { print "<div class="smain">Ошибка авторизации!</div>"; }
@mysql_close();
print '</body></html>';
?>