View file www/config.php

File size: 2.25Kb
<?php
$host = 'localhost';
$user = ''; 
$pass = ''; 
$dbname = '';
$title = 'Проект Wilaxia';
if(!mysql_connect($host,$user,$pass))
  die('Иди нах! MySQL в отключке!');
elseif(!mysql_select_db($dbname))
  die('Иди нах! В MySQL нет такой базы!');
 
mysql_query ("set character_set_client='cp1251'"); 
mysql_query ("set character_set_results='cp1251'"); 
mysql_query ("set collation_connection='cp1251_general_ci'"); 
$sait = 'http://wilaxia.ru';
define ("num_best_on_page",10);
define ("num_best_on_page2",5);
$userinfo='';
$state='0';
if( (isset($_COOKIE['email'])) & (isset($_COOKIE['pass'])) ) {
	$email = $_COOKIE['email'];
		preg_match("/^(?:[a-z0-9]+(?:[-_.]?[a-z0-9-_.]+)?@[a-z0-9]+(?:\.?[a-z0-9-.]+)?\.[a-z]{2,5})$/i",$email);
	if (!isset($_GET['exit'])) {
			$pass = strip_tags($_COOKIE['pass']); 
			$pass = trim($pass);
			$pass = htmlspecialchars($pass); 
			$pass = mysql_escape_string($pass);
			$sql="SELECT email, pass FROM users WHERE email='$email'";
			$res=mysql_query($sql);
		if(mysql_num_rows($res)>0){
			$userinfo = mysql_fetch_array($res);
			if(strcmp($pass,md5($userinfo['pass'])) == 0) {
				$sql="SELECT * FROM users WHERE email='$email'";
				$res=mysql_query($sql);
				$userinfo=mysql_fetch_array($res);
				$time=time();
				setcookie("email",$email,$time+1800);
				setcookie("pass",$pass,$time+1800);
				$state = 1;
			}
		}
	} else {
    setcookie("email");
    setcookie("pass");
	}
}
if($state != 1) {
	$email = $_POST['email'];
	preg_match("/^(?:[a-z0-9]+(?:[-_.]?[a-z0-9-_.]+)?@[a-z0-9]+(?:\.?[a-z0-9-.]+)?\.[a-z]{2,5})$/i",$email);
	if( (isset($_POST['email'])) & (isset($_POST['pass'])) ){	
	$sql = "SELECT email, pass FROM users WHERE email='$email'";
	$res = mysql_query($sql);
		if(mysql_num_rows($res)>0) {
			$userinfo = mysql_fetch_array($res);
			$pass = strip_tags($_POST['pass']); 
			$pass = trim($pass);
			$pass = htmlspecialchars($pass); 
			$pass = mysql_escape_string($pass); 
			if(strcmp($pass,$userinfo['pass'])==0){
				$sql="SELECT * FROM users WHERE email='$email'";
				$res=mysql_query($sql);
				$userinfo=mysql_fetch_array($res);
				$time=time();
				setcookie("email", $email, $time+1800);
				setcookie("pass", md5($pass), $time+1800);
				$state = 1;
			}
		}
	}
}
?>