Файл: test.masteram.us/comm/forum/files.php
Строк: 71
<?
include_once '../../sys/inc/start.php';
include_once '../../sys/inc/sess.php';
include_once '../../sys/inc/home.php';
include_once '../../sys/inc/settings.php';
include_once '../../sys/inc/db_connect.php';
include_once '../../sys/inc/ipua.php';
include_once '../../sys/inc/fnc.php';
include_once '../../sys/inc/user.php';
include_once '../../sys/inc/downloadfile.php';
if(isset($_GET['id_comm'])){
$id_comm = intval($_GET['id_comm']);
}else{
header("Location: /index.php");
}
$admin = mysql_fetch_array(mysql_query("SELECT * FROM `community_user_incomm` WHERE `cid` = '$id_comm' AND `uid` = '".$user['id']."'"));
$activate = mysql_fetch_array(mysql_query("SELECT * FROM `community_user_incomm` WHERE `cid` = '$id_comm' AND `uid` = '".$user['id']."' LIMIT 1"));
$comm = mysql_fetch_array(mysql_query('SELECT * FROM `community_comm` WHERE `id` = '.$id_comm.' LIMIT 1'));
if (isset($_GET['id']) && mysql_result(mysql_query("SELECT COUNT(*) FROM `comm_forum_files` WHERE `id` = '".intval($_GET['id'])."'"),0) && is_file(H.'sys/comm/forum/'.intval($_GET['id']).'.frf'))
{
$file=mysql_fetch_assoc(mysql_query("SELECT `id`,`name`,`ras` FROM `comm_forum_files` WHERE `id` = '".intval($_GET['id'])."' AND `id_comm` = '".$id_comm."' LIMIT 1"));
if (isset($_GET['del']) && isset($user) && $user['level'])
{
// удаление файла
if (isset($_SERVER['HTTP_REFERER']) && $_SERVER['HTTP_REFERER'])$link=$_SERVER['HTTP_REFERER'];else $link='/index.php';
mysql_query("DELETE FROM `comm_forum_files` WHERE `id` = '$file[id]' AND `id_comm` = '".$id_comm."' LIMIT 1");
unlink(H.'sys/comm/forum/'.$file['id'].'.frf');
header("Location: $link?".SID);
}
else
{
// скачивание файла
mysql_query("UPDATE `comm_forum_files` SET `count` = `count` + 1 WHERE `id` = '$file[id]' AND `id_comm` = '".$id_comm."' LIMIT 1");
DownloadFile(H.'sys/comm/forum/'.$file['id'].'.frf', $file['name'].'.'.$file['ras'],ras_to_mime($file['ras']));
exit;
}
}
else
{
//header("Refresh: 3; url=/index.php");
//header("Content-type: text/html",NULL,404);
$set['title']='Форум'; // заголовок страницы
include_once '../sys/inc/thead.php';
title();
aut();
$smarty = new Smarty_conf();
$smarty->assign('msg','Странно... Файл не найден...');
$smarty->display('page.notfound.tpl');
include_once '../../sys/inc/tfoot.php';
}
?>