1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84
| <?
session_start();
if(!session_is_registered("User_Login") || !session_is_registered("User_Pwd"))
{
print '<META HTTP-EQUIV="refresh" CONTENT="0; URL = index.php?msg=Mauvais+Login+et/ou+Password+!">';
exit;
}
?>
<?php include("includes/config.inc.php"); ?>
<?php
if($action == "envoie")
{
$A = $HTTP_POST_VARS["A"];
$objet = $HTTP_POST_VARS["objet"];
$message = $HTTP_POST_VARS["message"];
$auteur = $HTTP_POST_VARS["auteur"];
if($A == "")
{
echo "<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL = ?msg=Veuillez+choisir+un+destinataire+!\">";
exit;
}
if($objet == "")
{
echo "<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL = ?msg=Veuillez+saisir+un+objet+!\">";
exit;
}
if($message == "")
{
echo "<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL = ?msg=Veuillez+saisir+un+message+!\">";
exit;
}
$db = mysql_connect($sql_host,$sql_user,$sql_pass);
mysql_select_db($sql_bdd,$db);
$A = strip_tags($A);
$objet = strip_tags($objet);
$message = strip_tags($message);
$message = nl2br($message);
$sql = "SELECT User_Login FROM $tb_membres WHERE User_Login='$A' AND active='1'" or die (mysql_error());
$num = mysql_query($sql);
if (mysql_fetch_array($num))
{
$taille = 13;
$lettres = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
srand(time());
for ($i=0;$i<$taille;$i++)
{
$msg_ID.=substr($lettres,(rand()%(strlen($lettres))),1);
}
$date = time();
$sql = "INSERT INTO $tb_message (id, auteur, msg_ID, de, A, objet, message, lu, date) VALUES ('', '".$_COOKIE['connect_login']."', '$msg_ID', '".$_COOKIE['connect_login']."', '$A', '$objet', '$message', 'no', '$date')";
mysql_query($sql);
if($save == "yes")
{
$sql = "INSERT INTO $tb_envoi (id, auteur, msg_ID, de, A, objet, message, lu, date) VALUES ('', '".$_COOKIE['connect_login']."', '$msg_ID', '".$_COOKIE['connect_login']."', '$A', '$objet', '$message', 'no', '$date')";
mysql_query($sql);
}
echo "<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL = ?msg=Votre+message+à+bien+été+envoyé+!\">";
exit;
}
else
{
echo "<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL = ?msg=Une+erreur+est+survenue+lors+de+l'envoie+!\">";
exit;
}
mysql_close($db);
}
?> |
Partager