Файл: room.inc.php
Строк: 147
<?php
if ($room == "intim"){
print "<small><u><b>Здесь сейчас:</u> ";
$hq = @mysql_query("select `login` from `".$px.$utable."` where ltime>'".intval(time()-$offline)."' and `intimkey`='$key' and ci='$ci' and room='intim' order by ltime desc;;");
while($keydata = @mysql_fetch_array($hq)) {
$zd = $keydata['login'];
print "$zd,";
}
print '<div class="contur_rek"><div class="header_rek"></small><a href="./room.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'&key='.$key.'&room='.$room.'&r='.$r.'">Обновить</a>';
}else{
print '<div class="contur_rek"><div class="header_rek"><a href="./room.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'&room='.$room.'&r='.$r.'">Обновить</a>';
}
print " | <a href="./letters/index.php?s=$s&ci=$ci&id=$id&pass=$pass">".$lang['letters']."(".$num_in['count(*)']."/".$num_in_all['count(*)'].")</a> |
<a href="./online.php?s=$s&ci=$ci&id=$id&pass=$pass">".$lang['who_online']."</a></div></div>";
if ($room == "intim"){
print '<form action="room.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'&key='.$key.'&room='.$room.'&r='.$r.'" method="post">';
}else {
print '<form action="room.php?s='.$s.'&ci='.$ci.'&id='.$id.'&pass='.$pass.'&room='.$room.'&r='.$r.'" method="post">';
}
print '<input type="text" class="do_button" name="msg" maxlength="1000"/>'.
'<input type="submit" class="button" value="'.$lang['say'].'"></form><div class="contur"><div class="header">';
$ignor = "";
$qi = @mysql_query("select * from `".$px.$itable."` where loginid=".$login['id']." and ci='$ci';");
while($idata = @mysql_fetch_array($qi)) {
$ignor = "".$idata['user']."";
}
if ($ignor == "");
($ignor == "1");
if($login['moder'])
if ($act== "dell"){
if(@mysql_query("delete from `".$px.$mtable."` where `id`='$mid' ")) print $lang['dellmess'];
if(@mysql_query("delete from `".$px.$vtable."` where `id`='$mid' "));
else print $lang['errormess'];}
if($room=="vict") {
if($mod=="privat")
$que = @mysql_query("SELECT `id`,`login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$vtable."` WHERE login != '".$ignor."' and ci= '$ci' and (pr_to=".$login['id']." or pr_from=".$login['id'].") order by id desc limit $num_msgs;");
else
$que = @mysql_query("SELECT `id`,`login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$vtable."` WHERE ((pr_to = '' AND pr_from = '') OR (pr_from = '".$login['id']."' OR pr_to = '".$login['id']."')) and login != '".$ignor."' and ci= '$ci' order by id desc limit $num_msgs;");
}else{
if($mod=="privat")
$que = @mysql_query("SELECT `id`,`login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$mtable."` WHERE room = '$room' and login != '".$ignor."' and ci= '$ci' and (pr_to=".$login['id']." or pr_from=".$login['id'].") order by time desc limit $num_msgs;");
else
$que = @mysql_query("SELECT `id`,`login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$mtable."` WHERE ((pr_to = '' AND pr_from = '') OR (pr_from = '".$login['id']."' OR pr_to = '".$login['id']."')) and room = '$room' and ci= '$ci' and login != '".$ignor."' order by time desc limit $num_msgs;");
}
if ($room=="unlim"){
if($mod=="privat")
$que = @mysql_query("SELECT `login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$untable."` WHERE login != '".$ignor."' and ci= '$ci' and (pr_to=".$login['id']." or pr_from=".$login['id'].") order by time desc limit $num_msgs;");
else
$que = @mysql_query("SELECT `login`,`msg`,`time`,`pr_to`,`pr_from` from `".$px.$untable."` WHERE ((pr_to = '' AND pr_from = '') OR (pr_from = '".$login['id']."' OR pr_to = '".$login['id']."')) and ci= '$ci' and login != '".$ignor."' order by time desc limit $num_msgs;");
}
if ($room=="intim") {
$que = @mysql_query("SELECT `login`,`msg`,`time` from `".$px.$prtable."` WHERE ci= '$ci' and `key`='$key' order by time desc limit $num_msgs;");
}
$pr_to = 0;
$pr_from = 0;
while($m = @mysql_fetch_array($que)) {
$dblogin = $m['login'];
$dbmsg = $m['msg'];
$idmess = $m['id'];
$dbtime = ($m['time']);
if ($room == "intim"){
$pr_to == "";
$pr_from == "";
} else {
$pr_to = $m['pr_to'];
$pr_from = $m['pr_from'];}
// фильтрация вставки тегов
$dbmsg = str_replace("http://","",$dbmsg);
$dbmsg = str_replace(".ru","",$dbmsg);
$dbmsg = str_replace(".com","",$dbmsg);
$dbmsg = str_replace(".biz","",$dbmsg);
$dbmsg = str_replace(".kz","",$dbmsg);
$dbmsg = str_replace(".wen","",$dbmsg);
$dbmsg = str_replace(".wab","",$dbmsg);
$dbmsg = str_replace(".kmx","",$dbmsg);
$dbmsg = str_replace(".net","",$dbmsg);
$dbmsg = str_replace(".su","",$dbmsg);
$dbmsg = str_replace("<a href=","",$dbmsg);
$dbmsg = str_replace("`","",$dbmsg);
$dbmsg = str_replace("'","",$dbmsg);
$qdblogin = @mysql_query("select `id` from `".$px.$utable."` where `login`='$dblogin' and ci='$ci'");
$db = @mysql_fetch_array($qdblogin);
if(!empty($pr_to)&&!empty($pr_from)) print "<div class="smain"><a href="user.php?s=$s&ci=$ci&id=$id&pass=$pass&room=$room&dbid=".$db['id']."&r=$r&mod=$mod">$dblogin</a></u><b><font color=#FF0000>[Приват!]</font></b>r<span style="color:#FAA134;">[".date("H.i",$dbtime)."]</span>>".$dbmsg."<br>";
else
if ($room == "intim"){
print "<div class="smain"><a href="./user.php?s=$s&ci=$ci&id=$id&pass=$pass&key=$key&room=$room&dbid=".$db['id']."&r=$r">$dblogin</a></u>r<span style="color:#FAA134;">[".date("H.i",$dbtime)."]</span>>".$dbmsg."<br>";
}else{
if($login['moder']) print "[<a href="room.php?s=$s&ci=$ci&id=$id&pass=$pass&room=$room&r=$r&act=dell&mid=$idmess">x</a>]</option></select>";
print "<a href="./user.php?s=$s&ci=$ci&id=$id&pass=$pass&room=$room&dbid=".$db['id']."&&mid=".$idmess."&r=$r">$dblogin</a></u>r<span style="color:#FAA134;">[".date("H.i",$dbtime)."]</span>>".$dbmsg."<br>";
}}
if($mod=="privat")
print "<br/><div class="smain"><a href="./history.php?s=$s&ci=$ci&id=$id&pass=$pass&room=$room&start=$num_msgs&&mod=$mod&r=$r">История</a></div>";
else
?>