Файл: public_html/success.php
Строк: 207
<?
session_start();
include('funciones.php');
if($_SESSION["endtime"]>time())
{
    echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Ошибка! Просмотр не засчитан</span>";
    exit();
}
if(isset($_SESSION["username"]) && isset($_SESSION["password"]))
{
    require('config.php');
    $user=$_SESSION["username"];
    if(preg_match("|^[d]*$|",$_SESSION['ad'])) 
    {
        $adse=$_SESSION["ad"]; 
    }else{
        echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Ошибка! Просмотр не засчитан</span>";
        exit();
    }
    $res=mysql_query("select dopsec from tb_ads where id='$adse'");
    $res=mysql_fetch_array($res);
    $captcha=''; $ver='';
    if($res["dopsec"]=='2')
    {
        $captcha=$_POST["captcha"];
        $ver=$_SESSION["captcha"];
    }
    
    if(!isset($_GET["ds"]))
    {
        $checkad = mysql_query("SELECT id FROM tb_ads WHERE id='$adse' and tipo='ads'");
        $ad_exist = mysql_num_rows($checkad);
        if ($ad_exist<1)
        {
            echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Ссылка не существует</span>";
            exit();
        }
        if($res["dopsec"]=='1')
        {
            ?>
            <span style="vertical-align: middle;">
            <form method="post" action="vls.php?view=ok&ds=clicked" style="padding-top: 5px; vertical-align: middle;">
                 <input type="submit" value="Подтвердить просмотр">
            </form>
            </span>
            <?
            mysql_close($con);
            exit();
        }
        if($res["dopsec"]=='2')
        {
            ?>
            <span style="vertical-align: middle;">
            <form method="post" action="vls.php?view=ok&ds=clicked" style="padding-top: 5px; vertical-align: middle;">
            <img src="captcha.php" align="middle"> <input type=text value='' size=10 maxlength=3 name="captcha">
             <input type="submit" value="Подтвердить просмотр">
            </form>
            </span>
            <?
            mysql_close($con);
            exit();
        }
    }
    if(!isset($_GET["ds"]) or ($_GET["ds"]=='clicked' and $ver==$captcha))
    {
        $adse=$_SESSION["ad"];
        $querye = mysql_query("SELECT * FROM tb_ads WHERE user = '$user' and ident= '$adse'") or die(mysql_error());
        $rowe = mysql_fetch_array($querye);
        $time=$rowe['visitime'];
        $crok1 = date(time());
        $crok2 = date($time + 86400);
        if($crok1 >= $crok2)
        {
            $checkvisit = mysql_query("SELECT * FROM tb_ads WHERE user='$user' and ident='$adse'");
            $referer_visit = mysql_num_rows($checkvisit);
            $sqlz = "SELECT * FROM tb_ads WHERE id='$adse'";
            $resultz = mysql_query($sqlz);        
            $myrowz = mysql_fetch_array($resultz);
            $numero=$myrowz["members"];
            $jo=$myrowz["plan"];
            if ($numero >= $jo)
            {
                echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Ссылка не существует</span>";
                exit();
            }
            if ($referer_visit>0)
            {
                $queryzx = "UPDATE tb_ads SET visitime='$crok1' WHERE user='$user' and ident='$adse' and tipo='visit'";
                mysql_query($queryzx) or die(mysql_error());
            }else{
                $queryzz = "INSERT INTO tb_ads (user, ip, tipo, ident, visitime) VALUES('$user','','visit','$adse','$crok1')";
                mysql_query($queryzz) or die(mysql_error());
            }
            $sqlzd = "SELECT * FROM tb_users WHERE username='$user'";
            $resultzd = mysql_query($sqlzd);
            $myrowzd = mysql_fetch_array($resultzd);
            $juaz=$myrowzd["referer"];
            if ($juaz!="")
            {
                $sqlzde = "SELECT * FROM tb_users WHERE username='$juaz'";
                $resultzde = mysql_query($sqlzde);        
                $myrowzde = mysql_fetch_array($resultzde);
                $juaze=$myrowzde["referalvisits"];
                $billetes=$myrowzde["money"];
                $level=$myrowzde["account"];
                if($level!='V.I.P.')
                {
                    $sqlzdu = "SELECT * FROM tb_config WHERE item='referalclick' and howmany='1'";
                }else{
                    $sqlzdu = "SELECT * FROM tb_config WHERE item='viprefclick' and howmany='1'";
                }
                $resultzdu = mysql_query($sqlzdu);        
                $myrowzdu = mysql_fetch_array($resultzdu);
                $elprecio=$myrowzdu["price"];
    
                $sqlexd = "UPDATE tb_users SET referalvisits='$juaze'+1, money='$billetes'+'$elprecio' WHERE username='$juaz'";
                $resultexd = mysql_query($sqlexd);
            }
            $sqlex = "UPDATE tb_ads SET members='$numero'+1 WHERE id='$adse'";
            $resultex = mysql_query($sqlex);
            $sqlze = "SELECT * FROM tb_users WHERE username='$user'";
            $resultze = mysql_query($sqlze);        
            $myrowze = mysql_fetch_array($resultze);
            $visitas=$myrowze["visits"];
            $dinero=$myrowze["money"];
            $level=$myrowze["account"];
            if($level!='V.I.P.')
            {
                $sqlzdu = "SELECT * FROM tb_config WHERE item='click' and howmany='1'";
            }else{
                $sqlzdu = "SELECT * FROM tb_config WHERE item='vipclick' and howmany='1'";
            }
            $resultzdu = mysql_query($sqlzdu);        
            $myrowzdu = mysql_fetch_array($resultzdu);
            $elprecio=$myrowzdu["price"];
            $sqlexzz = "UPDATE tb_users SET visits='$visitas'+1, money='$dinero'+'$elprecio' WHERE username='$user'";
            $resultexzz = mysql_query($sqlexzz);
            $res=mysql_query("select * from tb_comp where param='3'");
            if(mysql_num_rows($res)>0)
            {
                while($row=mysql_fetch_array($res))
                {
                    $id=$row["id"];
                    $lidertype=$row["lidername"];
                    $t=time();
                    $sd=strtotime($row["startdate"]);
                    $ed=strtotime($row["enddate"]);
                    if($t>$sd && $t<$ed)
                    {
                        if($lidertype=='1')
                        {
                            $res1=mysql_query("select wmid from tb_users where username='$user'");
                            if(mysql_num_rows($res1)>0){$res1=mysql_fetch_array($res1); $lidername=$res1["wmid"];}else{$lidername='';}
                        }else{
                            $lidername=$user;
                        }
                        if($lidername!='')
                        {
                            $res1=mysql_query("select * from tb_compdata where idk='$id' and user='$lidername'");
                            if(mysql_num_rows($res1)>0)
                            {
                                $res1=mysql_Fetch_array($res1);
                                $resvalue=$res1["resvalue"]+1;
                                mysql_query("update tb_compdata set resvalue='$resvalue' where id='".$res1["id"]."'");
                            }else{
                                mysql_query("insert into tb_compdata (idk,user,resvalue) values ('$id','$lidername','1')");
                            }
                        }
                    }
                }
            }
            echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #00dd00;"> <img src="images/ok.png" align="middle"> Просмотр засчитан</span>";
        }else{
            echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Вы уже просматривали эту ссылку!</span>";
        }
    }else{
        echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Ошибка! Просмотр не засчитан</span>";
    }
    mysql_close($con);
}else{
    $juaz=date("n/j/Y H:i:s", $crok1);
    $juaze=date("n/j/Y H:i:s", $crok2);
    echo "<span style="border: medium none; padding: 0pt; font-size: 10pt; font-family: Verdana; font-weight: bold; vertical-align: top; color: #ff0000;"> <img src="images/error.png" align="middle"> Вам необходимо авторизоваться</span>";
}
?>