Файл: vkolhoze.com/inc/admin.spam.php
Строк: 103
<?
if(isset($_GET['add']))
{
echo "<div class='event'><h1><a href='?admin=$admin'>$admin_name</a> / Добавить</h1><title>$admin_name / Добавить</title></div>";
echo '<div class="content"><div class="block">';
if(isset($_POST['ok']))
{
$mask=$_POST['mask'];
$type=$_POST['type'];
mysql_query("INSERT INTO `fiter_text` SET `mask` = '$mask', `type` = '$type'");
header("location: ?admin=$admin");
}
echo "<form method="post">n";
echo "Слово:<br /><input name="mask" type="text" maxlength='32' style='width: 98%; padding: 3px;' value=''/><br />n";
echo "type:<br /><input name="type" type="text" maxlength='32' style='width: 98%; padding: 3px;' value=''/><br />n";
echo "<input value='Добавить' type='submit' name='ok' /><br />n";
echo "</form>n";
echo "</div>";
include_once 'inc/foot.php';
exit;
}
if(isset($_GET['edit']) && intval($_GET['edit'])!=NULL && mysql_result(mysql_query("SELECT COUNT(*) FROM `fiter_text` WHERE `id` = '".intval($_GET['edit'])."'"),0)!=0)
{
echo "<div class='event'><h1><a href='?admin=$admin'>$admin_name</a> / Редактировать</h1> <title>$admin_name / Редактировать</title></div>";
echo '<div class="content"><div class="block">';
$edit=mysql_fetch_array(mysql_query("SELECT * FROM `fiter_text` WHERE `id` = '".intval($_GET['edit'])."'"));
if(isset($_POST['ok']))
{
$mask=$_POST['mask'];
$type=$_POST['type'];
mysql_query("UPDATE `fiter_text` SET `mask` = '$mask', `type` = '$type' WHERE `id` = '$edit[id]'");
header("Location:?admin=$admin");
}
echo "<form method="post">n";
echo "Город:<br /><input name="mask" type="text" maxlength='32' style='width: 98%; padding: 3px;' value='$edit[mask]'/><br />n";
echo "type:<br /><input name="type" type="text" maxlength='32' style='width: 98%; padding: 3px;' value='$edit[type]' /><br />n";
echo "<input value='Сохранить' type='submit' name='ok' /></form>n";
echo "<div><br/><img width='16' height='16' src='images/icons/delete.png' alt=''><a href='?admin=$admin&del=$edit[id]'>Удалить</a></div>";
echo "</div>";
include_once 'inc/foot.php';
exit;
}
if(isset($_GET['del']) && mysql_result(mysql_query("SELECT COUNT(*) FROM `fiter_text` WHERE `id` = '".intval($_GET['del'])."'"),0)!=0)
{
$del=mysql_fetch_array(mysql_query("SELECT * FROM `fiter_text` WHERE `id` = '".intval($_GET['del'])."'"));
if(isset($_GET['ok']))
{
mysql_query("DELETE FROM `fiter_text` WHERE `id` = '$del[id]'");
header("Location:?admin=$admin");
}
podtv("?admin=$admin&del=$del[id]&ok","?admin=$admin");
echo "</div>";
include_once 'inc/foot.php';
exit;
}
echo "<div class='event'><h1><a href='?admin=list'>Админка</a> / $admin_name</h1> <title> $admin_name</title></div>";
echo '<div class="content"><div class="block">';
$k_post = mysql_result(mysql_query("SELECT COUNT(*) FROM `fiter_text`"),0);
if ($k_post==0)
{
echo "Список пуст...";
}
$k_page=k_page($k_post,$set['p_str']);
$page=page($k_page);
$start=$set['p_str']*$page-$set['p_str'];
$q=mysql_query("SELECT * FROM `fiter_text` ORDER BY `id` DESC LIMIT $start, $set[p_str]");
while($post=mysql_fetch_array($q))
{
echo "<li><img src='/images/icons/center.png'> <a href='?admin=$admin&edit=$post[id]'><span>$post[mask] </span></a> ( <span>ID $post[id]</span>)</li>";
}
if ($k_page>1)str("?admin=$admin&",$k_page,$page); // Вывод страниц
echo "<div><a href='?admin=$admin&add'>Добавить спам-слово</a></div>";
echo "</ul></div>";
include_once 'inc/foot.php';
exit;
?>