Advertisement
Guest User

Untitled

a guest
Jul 5th, 2017
265
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.63 KB | None | 0 0
  1. <?php
  2. $html = file_get_contents("guestbook.html");
  3. $username="usr_10746419";
  4. $password="746419";
  5. $database="db_10746419";
  6. $db = mysql_connect("atlas.dsv.su.se", $username,$password)
  7. or die("Unable to connect to sql server");
  8.  
  9. mysql_select_db($database,$db) or die("Unable to select database");
  10.  
  11. if(isset($_POST['submit'])){
  12.  
  13. $name=$_POST['name'];
  14. $comment=$_POST['comment'];
  15. $email=$_POST['email'];
  16. $homepage=$_POST['homepage'];
  17.  
  18.  
  19.  
  20. $query = "INSERT INTO guestbook (email, comment, name, surname, homepage)
  21. VALUES ('$email','$comment','$name','default','$homepage')";
  22. mysql_query($query,$db) or die("kek");
  23. echo "Using username :$username \n";
  24. echo "Using password :$password \n";
  25. echo "Using database :$database \n";
  26. }
  27. $query = "SELECT * FROM guestbook";
  28.  
  29. eval("print \"" . addcslashes(preg_replace("/(---(.+?)---)/", "\\2", $html), '"') . "\";");
  30.  
  31. if ($results = mysql_query($query, $db)) {
  32. while ($row = mysql_fetch_assoc($results)) {
  33. $comment =mysql_real_escape_string( htmlentities($row['comment']));
  34. $date = mysql_real_escape_string( htmlentities($row['date']));
  35. $id = mysql_real_escape_string( htmlentities($row['id']));
  36. $name = mysql_real_escape_string( htmlentities($row['name']));
  37. $email = mysql_real_escape_string( htmlentities($row['email']));
  38.  
  39. echo "<b>Inlägg ".$id." </b> <br /> <br />";
  40. echo "<b>Tid: </b> ".$date."<br />";
  41. echo "<b>Från:</b> ".$name." <br />";
  42. echo "<b>E-post: </b> ".$email." <br /> <br />";
  43. echo "<b>Kommentar:</b> ".$comment."<br /> <br /> ";
  44. }
  45. }
  46. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement