Файл: obmen/index.php
Строк: 303
<?
include_once '../sys/inc/start.php';
if (isset($_GET['showinfo']) || !isset($_GET['f']) || isset($_GET['komm']))
include_once '../sys/inc/compress.php';
include_once '../sys/inc/sess.php';
include_once '../sys/inc/home.php';
include_once '../sys/inc/settings.php';
include_once '../sys/inc/db_connect.php';
include_once '../sys/inc/ipua.php';
include_once '../sys/inc/fnc.php';
include_once '../sys/inc/obmen.php';
include_once '../sys/inc/user.php';
if (isset($_GET['d']) && esc($_GET['d'])!=NULL)
{
$l=ereg_replace(".{2,}",NULL,esc(urldecode($_GET['d'])));
$l=ereg_replace("./|/.",NULL,$l);
$l=ereg_replace("(/){1,}","/",$l);
$l='/'.ereg_replace("(^(/){1,})|((/){1,}$)","",$l);
}
else
{
$l='/';
}
if ($l=='/')
{
$dir_id['upload']=0;
$id_dir=0;
$l='/';
}
elseif (mysql_result(mysql_query("SELECT COUNT(*) FROM `obmennik_dir` WHERE `dir` = '/$l' OR `dir` = '$l/' OR `dir` = '$l' LIMIT 1"),0)!=0)
{
$dir_id=mysql_fetch_assoc(mysql_query("SELECT * FROM `obmennik_dir` WHERE `dir` = '/$l' OR `dir` = '$l/' OR `dir` = '$l' LIMIT 1"));
$id_dir=$dir_id['id'];
}
else
{
$dir_id['upload']=0;
$id_dir=0;
$l='/';
}
if (isset($_GET['f']))
{
$f=esc(urldecode($_GET['f']));
$name=eregi_replace('.[^.]*$', NULL, $f); // имя файла без расширения
$ras=strtolower(eregi_replace('^.*.', NULL, $f));
$ras=str_replace('jad', 'jar', $ras);
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `obmennik_files` WHERE `id_dir` = '$id_dir' AND `name`='$name' AND `ras` = '$ras' LIMIT 1"),0)!=0)
{
$file_id=mysql_fetch_assoc(mysql_query("SELECT * FROM `obmennik_files` WHERE `id_dir` = '$id_dir' AND `name`='$name' AND `ras` = '$ras' LIMIT 1"));
$ras=$file_id['ras'];
$file=H."sys/obmen/files/$file_id[id].dat";
$name=$file_id['name'];
$size=$file_id['size'];
if (!isset($_GET['showinfo']) && !isset($_GET['komm']) && is_file(H.'sys/obmen/files/'.$file_id['id'].'.dat'))
{
if ($ras=='jar' && strtolower(eregi_replace('^.*.', NULL, $f))=='jad')
{
include_once H.'sys/inc/zip.php';
$zip=new PclZip(H.'sys/obmen/files/'.$file_id['id'].'.dat');
$content = $zip->extract(PCLZIP_OPT_BY_NAME, "META-INF/MANIFEST.MF" ,PCLZIP_OPT_EXTRACT_AS_STRING);
$jad=eregi_replace("(MIDlet-Jar-URL:( )*[^(n|r)]*)", NULL, $content[0]['content']);
$jad=eregi_replace("(MIDlet-Jar-Size:( )*[^(n|r)]*)(n|r)", NULL, $jad);
$jad=trim($jad);
$jad.="rnMIDlet-Jar-Size: ".filesize(H.'sys/obmen/files/'.$file_id['id'].'.dat')."";
$jad.="rnMIDlet-Jar-URL: /obmen$dir_id[dir]$file_id[name].$file_id[ras]";
$jad=br($jad,"rn");
header('Content-Type: text/vnd.sun.j2me.app-descriptor');
header('Content-Disposition: attachment; filename="'.$file_id['name'].'.jad";');
echo $jad;
exit;
}
@mysql_query("UPDATE `obmennik_files` SET `k_loads` = '".($file_id['k_loads']+1)."' WHERE `id` = '$file_id[id]' LIMIT 1");
include_once '../sys/inc/downloadfile.php';
DownloadFile(H.'sys/obmen/files/'.$file_id['id'].'.dat', $name.'.'.$ras, ras_to_mime($ras));
/*
header("Content-type: $file_id[type]");
header("Content-Disposition: attachment; filename=$name.$ras");
header("Accept-Ranges: bytes");
header("Content-length: $file_id[size]");
echo file_get_contents(H.'sys/obmen/files/'.$file_id['id'].'.dat');
*/
exit;
}
elseif(isset($_GET['komm']) && is_file(H.'sys/obmen/files/'.$file_id['id'].'.dat'))
{
$set['title']='Обменник - Комментарии - '.$file_id['name']; // заголовок страницы
$_SESSION['page']=1;
include_once '../sys/inc/thead.php';
title();
include_once 'inc/komm_act.php'; // действия с комментариями
include_once 'inc/komm.php';
echo "<div class='foot'>";
echo "»<a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo'>К описанию</a><br />n";
echo "«<a href='/obmen$dir_id[dir]'>В папку</a><br />n";
echo "</div>n";
include_once '../sys/inc/tfoot.php';
exit;
}
else
{
$set['title']='Обменник - '.$file_id['name']; // заголовок страницы
include_once '../sys/inc/thead.php';
title();
include 'inc/file_act.php';
err();
aut(); // форма авторизации
########################
if (isset($user) && $user['balls']>=50 )
{
if (isset($_GET['raiting']) && $_GET['raiting']=='down' && $file_id[user_raiting]!=$user[nick] )
{
mysql_query("UPDATE `obmennik_files` SET `raiting` = '".($file_id['raiting']+1)."' WHERE `id` = '$file_id[id]' LIMIT 1",$db);
mysql_query("UPDATE `obmennik_files` SET `user_raiting` = '$user[nick]' WHERE `id` = '$file_id[id]' LIMIT 1",$db);
msg ('Ваш отзыв принят');}
################################################################################
if (isset($_GET['raiting']) && $_GET['raiting']=='www' && $file_id[user_raiting]!=$user[nick] )
{
mysql_query("UPDATE `obmennik_files` SET `raiting` = '".($file_id['raiting']+3)."' WHERE `id` = '$file_id[id]' LIMIT 3",$db);
mysql_query("UPDATE `obmennik_files` SET `user_raiting` = '$user[nick]' WHERE `id` = '$file_id[id]' LIMIT 3",$db);
################################################################################
msg ('Ваш отзыв принят');}
if (isset($_GET['raiting']) && $_GET['raiting']=='asd' && $file_id[user_raiting]!=$user[nick] )
{
mysql_query("UPDATE `obmennik_files` SET `raiting` = '".($file_id['raiting']+4)."' WHERE `id` = '$file_id[id]' LIMIT 4",$db);
mysql_query("UPDATE `obmennik_files` SET `user_raiting` = '$user[nick]' WHERE `id` = '$file_id[id]' LIMIT 4",$db);
msg ('Ваш отзыв принят');}
################################################################################
if (isset($_GET['raiting']) && $_GET['raiting']=='enk' && $file_id[user_raiting]!=$user[nick] )
{
mysql_query("UPDATE `obmennik_files` SET `raiting` = '".($file_id['raiting']+5)."' WHERE `id` = '$file_id[id]' LIMIT 5",$db);
mysql_query("UPDATE `obmennik_files` SET `user_raiting` = '$user[nick]' WHERE `id` = '$file_id[id]' LIMIT 5",$db);
msg ('Ваш отзыв принят');}
################################################################################
elseif(isset($_GET['raiting']) && $_GET['raiting']=='up'&& $file_id[user_raiting]!=$user[nick] ){
mysql_query("UPDATE `obmennik_files` SET `raiting` = '".($file_id['raiting']+2)."' WHERE `id` = '$file_id[id]' LIMIT 2",$db);
mysql_query("UPDATE `obmennik_files` SET `user_raiting` = '$user[nick]' WHERE `id` = '$file_id[id]' LIMIT 2",$db);
msg ('Ваш отзыв принят');$ank=mysql_fetch_array(mysql_query("SELECT * FROM `user` WHERE `id` = $ank[id] LIMIT 2"));}
}
################################################################################
echo "<div class='rekl'>";
echo "<font color='#8ACC00'><b>$file_id[name].$ras</b></font><br />";
if(is_file("inc/file/$ras.php"))include "inc/file/$ras.php";
else
include_once 'inc/file.php';
################################################################################
echo "<span class="ank_n">Рейтинг: $file_id[raiting]</span><br />";
echo "<span class="ank_n">Загрузок: $file_id[k_loads]</span><br />";
################################################################################
if ( $file_id[user_raiting]!=$user[nick] ){echo "<a href="/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo&raiting=down" title="Отдать отрицательный голос">+1</a> | ";}
if( $file_id[user_raiting]!=$user[nick] ){echo " <a href="/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo&raiting=up" title="Отдать положительный голос">+2</a> | ";
if( $file_id[user_raiting]!=$user[nick] ){echo " <a href="/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo&raiting=www" title="Отдать положительный голос">+3</a> | ";
if( $file_id[user_raiting]!=$user[nick] ){echo " <a href="/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo&raiting=asd" title="Отдать положительный голос">+4</a> | ";
if( $file_id[user_raiting]!=$user[nick] ){echo " <a href="/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]?showinfo&raiting=enk" title="Отдать положительный голос">+5</a>";
echo "<br />n";}}}}
################################################
################################################################################
/*if ($file_id['ras']=='jar')
echo "Файл: <a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".jad'>$file_id[name]</a> <a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]'>JAR</a><br />n";
else
echo "Файл: <a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]'>$file_id[name]</a><br />n";
*/
################################################################################
echo "</div>";
echo "<div class='rekl'>";
if ($file_id['ras']=='jar')
echo "<a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".jad'>[Загрузить]</a> <a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]'>JAR</a><br />n";
else
echo "<a href='/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]'>[Загрузить]</a><br />n";
echo "URL:<br /><input type='text' value='http://$_SERVER[SERVER_NAME]/obmen$dir_id[dir]".urlencode($file_id['name']).".$file_id[ras]' /><br />n";
echo "</div>n";
include_once 'inc/komm.php';
echo "<div class='rekl'><a href='/obmen$dir_id[dir]'>← В папку</a></div>n";
################################################################################
include 'inc/file_form.php';
include_once '../sys/inc/tfoot.php';
}
}
}
include_once 'inc/dir.php';
include_once '../sys/inc/tfoot.php';
?>