LoadVariables('get');
$page_title = stripslashes(str_replace( '_', ' ', $REWRITE[1]));
include('header.php');
//debug($REWRITE);
$do = new Query;
mysql_query("UPDATE shocks SET s_clicks = (s_clicks + 1) WHERE s_id = '".$REWRITE[2]."'");
if(isset($_POST['newsId'])) {
if(trim($_POST['name']) != '') {
$name = addslashes(trim($_POST['name']));
} else {
$errors[] = 'Please enter a name.
';
}
if(trim($_POST['comment']) != '') {
$comment = addslashes(trim($_POST['comment']));
} else {
$errors[] = 'Please enter a comment
';
}
if(check_email(trim($_POST['email']))) {
$email = trim($_POST['email']);
} else {
$errors[] = 'Wrong email format
';
}
if($_POST['securityCode'] != $_SESSION['security_code']) {
$errors[] = 'Wrong security code
';
}
if(empty($errors)) {
$do = new Query;
$sql = "INSERT INTO shocks_reviews (sr_site_id, sr_content, sr_from, sr_entry_date, sr_email)
VALUES ('".$REWRITE[2]."','".$comment."','".$name."',NOW(),'".$email."')";
$do->doQuery($sql);
//relocate('shock_profile.php?id='.$REWRITE[2]);
}
}
$sql = "SELECT s_entry_date as n_entry_date, s_title as n_title, s_content as n_content, name, s_image_path FROM shocks WHERE s_id = '".$REWRITE[2]."';";
$do->doQuery($sql);
$content = $do->getRows();
$row=mysql_fetch_array(mysql_query("select * from shocks where s_id='".$REWRITE[2]."'"));
?>
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||