<?
Error_Reporting(E_ALL & ~E_NOTICE); /////////////// игнорируем ошибки
header ("Content-type:text/vnd.wap.wml; charset=utf-8");
list($msec,$sec)=explode(chr(32),microtime());
$HeadTime=$sec+$msec;
$rand=rand(10000,1000000);
require("../conf.inc.php");
global $REMOTE_ADDR;
global $HTTP_USER_AGENT;
$id=@mysql_escape_string($id);
$pass=@mysql_escape_string($pass);
$login=@mysql_escape_string($login);
$link=mysql_pconnect ($DB_HOST, $DB_USER, $DB_PASS);
mysql_select_db($DB_NAME);
if(empty($id)) {
$find_user=mysql_query("Select * from users where cid='".$cid."' AND login='".$login."' and pass='".$pass."'") or die("Querry error");
} else {
$find_user=mysql_query("Select * from users where cid='".$cid."' AND id='".$id."' and pass='".$pass."'") or die("Querry error");
}
if(mysql_affected_rows()==0)
{
echo <<<END
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="search" title="РџРѕРСвЂВВВРЎРѓР С”">
<p align="center">
Логин или пароль неверны, проверьте ваш ввод.
</p>
</card>
</wml>
END;
return 0;
}
else
{
$row=mysql_fetch_array($find_user);
$login=$row['login'];
$id=$row['id'];
$admin=$row['admin'];
$status=$row['status'];
$posts=$row['posts'];
if (($row["browser"]!==$HTTP_USER_AGENT) or ($row["ip"]!==$REMOTE_ADDR))
{
mysql_query("update users set browser='$HTTP_USER_AGENT', ip='$REMOTE_ADDR' where cid='".$cid."' AND id='$id';");
}
//Проверка, не забанен ли ip+browser:
mysql_query ("Select * from bannedib WHERE cid='".$cid."' AND (ip = '".$REMOTE_ADDR."')and(browser = '".$HTTP_USER_AGENT."')");
if(mysql_affected_rows()!=0)
{
echo <<<END
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="error" title="Забанен">
<p align="center">
Вы забанены по связке ip+browser!
</p>
</card>
</wml>
END;
exit;
}
echo "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n";
echo "<!DOCTYPE wml PUBLIC \"-//WAPFORUM//DTD WML 1.2//EN\" \"http://www.wapforum.org/DTD/wml12.dtd\">\n";
echo "<wml>\n";
echo "<card title=\"Входящие\">\n";
echo "<p align=\"left\">\n";
if($row['fsize'] == "small") { $fsize1 = "<small>"; $fsize2 = "</small>"; }
elseif($row['fsize'] == "big") { $fsize1 = "<big>"; $fsize2 = "</big>"; }
else { $fsize1 = ""; $fsize2 = ""; }
if(empty($start)) $start = 0;
if($start < 0) $start = 0;
$pnumber = 5;
$tot=@mysql_query("select count(*) from letters where cid='".$cid."' AND to_user='$login'");
$lets=@mysql_query("select * from letters where cid='".$cid."' AND to_user='$login' order by time desc limit ".$start.",".$pnumber."");
if($tot && $lets) {
$total=@mysql_fetch_array($tot);
$count=$total['count(*)'];
while($data=@mysql_fetch_array($lets))
{
$from=$data['from_user'];
$to=$data['to_user'];
$time=$data['time'];
$subject=$data['subject'];
$letter=$data['letter'];
$new=$data['new'];
$id_letter=$data['id'];
$time=date("d.m.Y H:i", $time);
if($new) {
print "<b><a href=\"view.php?id=$id&pass=$pass&id_letter=$id_letter&cid=$cid&ref=$rand\">$subject [$time]</a></b><br/>";
}
else {
print "<a href=\"view.php?id=$id&pass=$pass&id_letter=$id_letter&cid=$cid&ref=$rand\">$subject [$time]</a><br/>";
}
}
}
if($start>0)
print "<a href=\"inbox.php?id=$id&pass=$pass&room=$room&start=".($start-$pnumber)."&cid=$cid&ref=$rand\">Предыдущие</a>";
if($count>$start+$pnumber)
print "<a href=\"inbox.php?id=$id&pass=$pass&room=$room&start=".($start+$pnumber)."&cid=$cid&ref=$rand\"><br/>Следующие</a>";
print "<br/><a href=\"../enter.php?id=$id&pass=$pass&cid=$cid&ref=$rand\">Прихожая</a><br/>";
}
?>
</p>
</card>
</wml>
<?
mysql_close($link);
?>