fork download
  1. $sql = "SELECT
  2. id,
  3. DATE_FORMAT(datum, '%d.%m.%Y') as datum,
  4. name,
  5. beschreibung,
  6. zip,
  7. screen,
  8. hits,
  9. anschau_link,
  10. (rating_summe/rating_anzahl) as rating,
  11. art,
  12. autor,
  13. benuetzt,
  14. autor_detail,
  15. autor_demo,
  16. self
  17. FROM
  18. free_webdesign
  19. WHERE
  20. id = '".mysql_real_escape_string($_GET['id'])."'
  21. ORDER BY
  22. datum DESC
  23. LIMIT
  24. 1
  25. ";
  26. $result = mysql_query($sql) OR die("<pre>\n".$sql."</pre>\n".mysql_error());
  27. if (mysql_num_rows($result) == 0) {
  28. §appbody .= "<div class=\"fehler\">Dieses Webdesign existiert nicht!</div>";
  29. }
  30. while ($row = mysql_fetch_assoc($result)) {
  31. §appbody .= '<div class="xis">
  32. <div class="i">
  33. <div class="io">
  34. <div class="ioi">
  35. Infos:
  36. </div>
  37. </div>
  38. <div class="im"><div class="imi">';
  39. if ($row['autor'] == '') {
  40. $autor = 'celzekr';
  41. }
  42. else {
  43. $autor = "<a href=\"index.php?section=user&name=".nocss($row['autor'])."\">".nocss($row['autor'])."</a>";
  44. }
  45. if ($row['benuetzt'] == '0') {
  46. $benuetzt = 'HTML, CSS';
  47. }
  48. else {
  49. $benuetzt = nocss($row['benuetzt']);
  50. }
  51. §appbody .= "<b>Autor</b>: ".$autor."<br>";
  52. §appbody .= "<b>Datum</b>: ".nocss($row['datum'])."<br>\n";
  53. §appbody .= "<b>Downloads</b>: ".nocss($row['hits'])."<br>\n";
  54. §appbody .= "<b>Bewertung</b>: ".nocss($row['rating'])."<br>";
  55. §appbody .= "<b>Benützt</b>: ".$benuetzt."<br>";
  56. if ($row['self'] == '1') {
  57. $anschauen = "http://f...content-available-to-author-only...t.de/thumbshot-pro/?scale=4&url=http://c...content-available-to-author-only...r.tk/".nocss($row['anschau_link'])."&effect=2";
  58. }
  59. else {
  60. $anschauen = "".nocss($row['autor_demo'])."";
  61. }
  62. §appbody .= '
  63. </div></div>
  64. <div class="iu">
  65. <div class="iui">
  66. </div>
  67. </div>
  68. </div>
  69. </div>
  70. <div class="b"><div class="bo"><div class="boi">'.nocss($row['name']).':</div>
  71. </div><div class="bm"><div class="bmi">
  72. <div class="news">
  73. <table>
  74. <tr>
  75. <td>
  76. <img class="wdimg" src="'.$anschauen.'" alt="">
  77. </td>
  78. <td>
  79. <div class="text2">
  80. '.nocss($row['beschreibung']).'
  81. </div>
  82. </td></tr>
  83. </table>
  84. </div>
  85. </div></div><div class="bu"><div class="bui">';
  86. if ($row['self'] == '1') {
  87. §appbody .= "<a href=\"anschauen.php?link=".nocss($row['anschau_link'])."\">Anschauen</a>&nbsp;&nbsp;<a href=\"index.php?section=ip&action=http://c...content-available-to-author-only...r.tk/".nocss($row['zip'])."\">Download (.zip)</a><br><br>\n";
  88. }
  89. else {
  90. §appbody .= "<a href=\"".nocss($row['autor_demo'])."\">Anschauen</a>&nbsp;&nbsp;<a href=\"".nocss($row['autor_detail'])."\">Details / Download</a><br><br>\n";
  91. }
  92. §appbody .= '</div></div></div><div class="b"><div class="bo"><div class="boi">
  93. Kommentare:
  94. </div>
  95. </div><div class="bm"><div class="bmi">';
  96. $sql555 = "SELECT
  97. id,
  98. autor,
  99. design_id,
  100. comment,
  101. date
  102. FROM
  103. design_comments
  104. WHERE
  105. design_id = '".$row['id']."'
  106. ORDER BY
  107. date DESC
  108. ";
  109. $result555 = mysql_query($sql555) OR die("<pre>\n".$sql555."</pre>\n".mysql_error());
  110.  
  111. while ($row555 = mysql_fetch_assoc($result555)) {
  112. §appbody .= "<div class=\"comment\"><b>Geschrieben von: ".nocss($row555['autor'])." am: ".nocss($row555['date'])."</b><br>".nocss($row555['comment'])."</div>\n";
  113. }
  114. if(isset($_POST['submit']) AND $_POST['submit'] == "Kommentieren") {
  115. if(empty($_REQUEST['comment']) || empty($_REQUEST['name']))
  116. {
  117. §appbody .= "<div class=\"fehler\">Bitte geben Sie Ihren Kommentar und Ihren Namen ein!</div>";
  118. }
  119. elseif(isset($_POST['email']) && $_POST['email']) {
  120. §appbody .= "<div class=\"fehler\">You are an SPAM-Bot!</div>";
  121. }
  122. else {
  123. $bodynachricht = parse_bbcode(mysql_real_escape_string($_REQUEST['comment']));
  124. mysql_query("INSERT INTO design_comments (autor, design_id, comment, date) VALUES ('".mysql_real_escape_string($_REQUEST['name'])."','".$row['id']."','".$bodynachricht."',now())");
  125. §appbody .= "<div class=\"erfolg\">Sie haben den Kommentar eingetragen.</div>";
  126. header("Location: http://c...content-available-to-author-only...r.tk/index.php?site=design&id=".$row['id']."");
  127. }
  128. }
  129. §appbody .= '
  130. <br><form action="index.php?site=design&id='.nocss($row['id']).'" method="post">
  131. <p class="hallo">
  132. <label for="email">Ihre eMail wird nicht abgefragt, tragen Sie auch hier bitte NICHTS ein:</label>
  133. <input id="email" name="email" size="60" value="" />
  134. </p>
  135. Kommentar schreiben: <br>
  136. <textarea id="nachricht" class="li" name="comment" cols="40" rows="5"></textarea>
  137. <br>
  138. Ihr Name: <input class="li" type="text" name="name"><br>
  139. <input class="lb" name="submit" type="submit" value="Kommentieren">
  140. </form>
  141. </div></div><div class="bu"><div class="bui"></div></div></div>';
  142. }
Success #stdin #stdout 0.01s 20520KB
stdin
Standard input is empty
stdout
$sql = "SELECT
            id,
            DATE_FORMAT(datum, '%d.%m.%Y') as datum,
            name,
            beschreibung,
		    zip,
			screen,
			hits,
			anschau_link,
            (rating_summe/rating_anzahl) as rating,
			art,
			autor,
			benuetzt,
			autor_detail,
			autor_demo,
			self
        FROM
            free_webdesign
		WHERE
		    id = '".mysql_real_escape_string($_GET['id'])."'
        ORDER BY
            datum DESC
		LIMIT 
		    1
		";
    $result = mysql_query($sql) OR die("<pre>\n".$sql."</pre>\n".mysql_error());
			if (mysql_num_rows($result) == 0) {
§appbody .= "<div class=\"fehler\">Dieses Webdesign existiert nicht!</div>";
	}
    while ($row = mysql_fetch_assoc($result)) {
§appbody .= '<div class="xis">
<div class="i">
<div class="io">
<div class="ioi">
Infos:
</div>
</div>
<div class="im"><div class="imi">';
if ($row['autor'] == '') {
$autor = 'celzekr';
}
else {
$autor = "<a href=\"index.php?section=user&name=".nocss($row['autor'])."\">".nocss($row['autor'])."</a>";
}
if ($row['benuetzt'] == '0') {
$benuetzt = 'HTML, CSS';
}
else {
$benuetzt = nocss($row['benuetzt']);
}
§appbody .= "<b>Autor</b>: ".$autor."<br>";
§appbody .= "<b>Datum</b>: ".nocss($row['datum'])."<br>\n";
§appbody .= "<b>Downloads</b>: ".nocss($row['hits'])."<br>\n";
§appbody .= "<b>Bewertung</b>: ".nocss($row['rating'])."<br>";
§appbody .= "<b>Benützt</b>: ".$benuetzt."<br>";
if ($row['self'] == '1') {
$anschauen = "http://f...content-available-to-author-only...t.de/thumbshot-pro/?scale=4&url=http://c...content-available-to-author-only...r.tk/".nocss($row['anschau_link'])."&effect=2";
}
else {
$anschauen = "".nocss($row['autor_demo'])."";
}
§appbody .= '
</div></div>
<div class="iu">
<div class="iui">
</div>
</div>
</div>
</div>
		<div class="b"><div class="bo"><div class="boi">'.nocss($row['name']).':</div>
		</div><div class="bm"><div class="bmi">
<div class="news">
<table>
<tr>
<td>
<img class="wdimg" src="'.$anschauen.'" alt="">
</td>
<td>
<div class="text2">
'.nocss($row['beschreibung']).'
</div>
</td></tr>
</table>
</div>
		</div></div><div class="bu"><div class="bui">';
if ($row['self'] == '1') {
§appbody .= "<a href=\"anschauen.php?link=".nocss($row['anschau_link'])."\">Anschauen</a>&nbsp;&nbsp;<a href=\"index.php?section=ip&action=http://c...content-available-to-author-only...r.tk/".nocss($row['zip'])."\">Download (.zip)</a><br><br>\n";
}
else {
§appbody .= "<a href=\"".nocss($row['autor_demo'])."\">Anschauen</a>&nbsp;&nbsp;<a href=\"".nocss($row['autor_detail'])."\">Details / Download</a><br><br>\n";
}
§appbody .= '</div></div></div><div class="b"><div class="bo"><div class="boi">
Kommentare:
</div>
		</div><div class="bm"><div class="bmi">';
    $sql555 = "SELECT
	                id,
	                autor,
                    design_id,
					comment,
					date
            FROM
                    design_comments
            WHERE
			        design_id = '".$row['id']."'
            ORDER BY
                    date DESC
           ";
    $result555 = mysql_query($sql555) OR die("<pre>\n".$sql555."</pre>\n".mysql_error());

    while ($row555 = mysql_fetch_assoc($result555)) {
§appbody .= "<div class=\"comment\"><b>Geschrieben von: ".nocss($row555['autor'])." am: ".nocss($row555['date'])."</b><br>".nocss($row555['comment'])."</div>\n";
    }
  if(isset($_POST['submit']) AND $_POST['submit'] == "Kommentieren") {
        if(empty($_REQUEST['comment']) || empty($_REQUEST['name']))
      {
§appbody .= "<div class=\"fehler\">Bitte geben Sie Ihren Kommentar und Ihren Namen ein!</div>";
      }
	  elseif(isset($_POST['email']) && $_POST['email']) {
§appbody .= "<div class=\"fehler\">You are an SPAM-Bot!</div>";
	  }
	  else {
	  $bodynachricht = parse_bbcode(mysql_real_escape_string($_REQUEST['comment']));
	  mysql_query("INSERT INTO design_comments (autor, design_id, comment, date) VALUES ('".mysql_real_escape_string($_REQUEST['name'])."','".$row['id']."','".$bodynachricht."',now())");
§appbody .= "<div class=\"erfolg\">Sie haben den Kommentar eingetragen.</div>";
	  header("Location: http://c...content-available-to-author-only...r.tk/index.php?site=design&id=".$row['id']."");
	  }
  }
§appbody .= '
<br><form action="index.php?site=design&id='.nocss($row['id']).'" method="post">
<p class="hallo">
  <label for="email">Ihre eMail wird nicht abgefragt, tragen Sie auch hier bitte NICHTS ein:</label>
  <input id="email" name="email" size="60" value="" />
</p>
          Kommentar schreiben: <br>
          <textarea id="nachricht" class="li" name="comment" cols="40" rows="5"></textarea>
          <br>
		  Ihr Name: <input class="li" type="text" name="name"><br>
          <input class="lb" name="submit" type="submit" value="Kommentieren">
      </form>
</div></div><div class="bu"><div class="bui"></div></div></div>';
    }