Файл: Kagao-v3.0/upload/meineanzeigen.php
Строк: 144
<?php
require('classes/config.php');
if(isset($_GET['logout'])){
    session_start();
    include "inc/db.php";
    unset($_SESSION['login']);
    $e->location('mainmeineanzeigen');
    die;    
}
if($_GET['sk'] != 'cancel'){
if($_GET['sk'] == 'checkout'){ session_start();
    include "inc/db.php";
    
    //checkout->paypal
    $tx     = $_GET['tx'];
    $item     = explode('|',$_GET['item_number']);
    
        $item_number     = $item[0];
        $highlight        = $item[1];
        $hochschieben    = $item[2];
        $galerie        = $item[3];
        
        $adddays         = strtotime('+10 days');
        
        if( $galerie == 1 ){
            $addGalerieTime_time = $adddays;
            $addGalerieTime = date('d.m.Y', $addGalerieTime_time);
            
            $e->query('UPDATE produkte SET
                ad_galerie            = "'.$addGalerieTime.'",
                ad_galerie_time        = "'.$addGalerieTime_time.'"
                WHERE    id            = "'.$item_number.'"
            ');
            
            $e->query('INSERT INTO paypal SET
                tx         = "'.$tx.'",
                amount     = "'.$_GET['amt'].'",
                item     = "'.$item_number.'",
                datum    = "'.time().'",
                arted      = "galerie",
                uid     = "'.$_SESSION['login'].'"
            ');
            
        }else{ $addGalerieTime = ''; $addGalerieTime_time = ''; }
        
        if( $hochschieben == 1 ){
            $addHochschiebenTime = time();
            $addHochschiebenTime_Date = date('d.m.Y', $addHochschiebenTime);
            
            $e->query('UPDATE produkte SET
                ad_hochschieben        = "'.$addHochschiebenTime_Date.'",
                ad_hochschieben_time= "'.$addHochschiebenTime.'"
                WHERE    id            = "'.$item_number.'"
            ');
            
            $e->query('INSERT INTO paypal SET
                tx         = "'.$tx.'",
                amount     = "'.$_GET['amt'].'",
                item     = "'.$item_number.'",
                datum    = "'.time().'",
                arted      = "upad",
                uid     = "'.$_SESSION['login'].'"
            ');
            
        }else{
            $addHochschiebenTime = '';
        }    
        
        if( $highlight == 1 ){
            $addHighlightTime_time = $adddays;
            $addHighlightTime = date('d.m.Y', $addHighlightTime_time);
            
            $e->query('UPDATE produkte SET
                ad_highlight        = "'.$addHighlightTime.'",
                ad_highlight_time    = "'.$addHighlightTime_time.'"
                WHERE    id            = "'.$item_number.'"
            ');
            
            $e->query('INSERT INTO paypal SET
                tx         = "'.$tx.'",
                amount     = "'.$_GET['amt'].'",
                item     = "'.$item_number.'",
                datum    = "'.time().'",
                arted      = "highlight",
                uid     = "'.$_SESSION['login'].'"
            ');
            
        }else{
            $addHighlightTime_time = ''; $addHighlightTime = '';
        }
        
    
    $e->location('mainmeineanzeigen?complete');
    die;
        
    
}
if($_GET['sk'] == 'success'){ session_start();
        include "inc/db.php";
        
        if(!empty($_GET['tx']) or !empty($_GET['amt']) or !empty($_GET['item_number'])){
        
            $a = $taggebuhr;
            
            if($_GET['amt'] == '2.00'){
                $add = strtotime('+2 days');    
            }else if($_GET['amt'] == '10.00'){
                $add = strtotime('+8 days');
            }else if($_GET['amt'] == '15.00'){
                $add = strtotime('+15 days');
            }else if($_GET['amt'] == '25.00'){
                $add = strtotime('+1 month');
            }
            
            $ende = date('d.m.Y', $add);
        
            $e->query('UPDATE produkte SET topanzeige = "1", topbis = "'.$ende.'" WHERE id = "'.$_GET['item_number'].'"');
            
            $e->query('INSERT INTO paypal SET
                tx = "'.$_GET['tx'].'",
                amount = "'.$_GET['amt'].'",
                item = "'.$_GET['item_number'].'",
                datum = "'.time().'",
                uid = "'.$_SESSION['login'].'"
            ');
                
        }
        
        $e->location('mainmeineanzeigen?complete');
        die;
            
}
else if($_GET['sk']){
    
    session_start();
    include "inc/db.php";
    
    $sk = htmlspecialchars($_GET['sk']);
    $id = intval($_GET['id']);
    
    switch($sk){
        case 'dec':
            $e->query('
                UPDATE     produkte 
                SET     statuscode = "2"
                WHERE     uid = "'.$_SESSION['login'].'" AND id = "'.$id.'"
            ');
            $e->location('mainmeineanzeigen');
            die;
        break;
        case 'act':
            $e->query('
                UPDATE     produkte 
                SET     statuscode = "1", erstellung = "'.time().'"
                WHERE     uid = "'.$_SESSION['login'].'" AND id = "'.$id.'"
            ');
            $e->location('mainmeineanzeigen');
            die;
        break;
        case 'delproduct':
            $e->query('
                DELETE FROM produkte
                WHERE uid = "'.$_SESSION['login'].'" AND id = "'.$id.'"
            ');
            $e->location('mainmeineanzeigen');
            die;
        break;
    }
    
    die;
}
}
    include "inc/rain.tpl.class.php";
    include "inc/db.php";
    include "inc/kategorie.php";
    include "inc/extra.php";
    include "inc/produkt.php";
    
    $db = new db();
    
    if( $_SESSION['mobile'] == 'on' and module_mobile == 1 ){
        
    raintpl::configure("base_url", null );
    raintpl::configure("tpl_dir", "tpl/m/" );
    raintpl::configure("cache_dir", "tmp/m/" );
        
    }else{
    
    raintpl::configure("base_url", null );
    raintpl::configure("tpl_dir", "tpl/" );
    raintpl::configure("cache_dir", "tmp/" );
    }
    //->artikel->vorhanden
        
        if(!empty($_SESSION['login'])){
        
        $_db = $db->query('SELECT id FROM produkte WHERE uid = "'.$_SESSION['login'].'"');
        $row = $db->fetch_assoc($_db);
        
        if(empty($row['id'])){
            
            $e->location('index.php?create=new');
            die;
                
        }
        
        }
    $tpl = new RainTPL;
    
    include "load.php";
    
    //PayPal
        $pp = $db->query('SELECT paypalid FROM pp WHERE id = "1"');
        $pc = $db->fetch_assoc($pp);
    //
    
    $info = array( 'title'        => $title8,
                   'copyright'     => $copyright,
                   'page'        => 'meineanzeigen',
                   'isLogin'    =>  $_SESSION['login'] ? true : false,
                   'paypalid'    => $pc['paypalid'],
                   'paypalacc'    => $paypalaccept,
                   'paypaldec'    => $paypalnone,
                   'tags'        => $taggebuhr
                   );
    $tpl->assign( $info );
    
    #->Kategorien
    $cat = new controller_cate();
    $tpl->assign("cats", $cat->getCategory());
    
    $ext = new extras();
    $tpl->assign("letzte", $ext->getList2());
    
    $html = $tpl->draw( 'page', $return_string = true );
    echo $html;
        
        class str{
            function cut($t){
                return substr($t, 1, 2 );
            }
        }
        
?>