Орла
Области
Компаний
Пользователи
Галерея
Фиксированные новости
Орла
Отзывы о фирмах
Тарифы
Пользователи
Области
Банкоматы
Торговые точки
Доска объявлений
Курсы валют
Скидки
организации Орла
организации области
товары
сайты
сайты Орел
Данные
Разделы
Поиск
Поиск запросы
Статистика
Показы каталога организаций
Статистика клиенты
Пользователи
Сайты
Управление сайтом
Анкета
Аптеки
Афиша
Афиша новая
Баннеры
Бизнес >
Викторина
Голосование
Гость на сайте
Истории
Календарь событий
Каталоги >
Конкурс красоты
Конкурс аудио
Консультации
Меню
Новое на сайте
Новости >
Организации >
Программа ТВ
Публикации
Разделы сайта
Рассылка
Рестораны
Секрет фирмы >
Сервисы >
Ссылки
Тесты
Файловый менеджер
Форум
Фотогалерея
Обратная связь
Недвижимость
Новый год
Тексты
Пользователи
Юридический рейтинг
Отзывы на товары
Бан пользователей
Жалобы
Новые тесты
Коронавирус
Файловый менеджер
Имя файла
action.php
Содержимое
<?php $base_url="../"; require_once($base_url.'func.php'); require_once('JSON.php'); $l = db_connect(); function array_first_keyword(&$elem) { $elem = current(array_splice(preg_split('/[\.,]/', $elem), 0,1)); } switch ( $_REQUEST['action'] ) { case 'search': $_GET['term'] = iconv("UTF-8", "WINDOWS-1251", $_GET['term']); $_GET['term'] = preg_replace("/[ ]+/", " ", trim($_GET['term'])); $_GET['term'] = mysql_real_escape_string($_GET['term']); $result = fetchAll( "select distinct street from firma where street like '%{$_GET['term']}%' limit 10" ); foreach ( $result as $row ) $json_result[] = $row['street']; echo json_encode_cyr($json_result); break; case 'load_locality': $_GET['id'] = (int) $_GET['id']; $result = fetchAll( "select id, name from locality where sub_admn_area_id = '{$_GET['id']}' order by name" ); foreach ( $result as $row ) $json_result[] = array('id'=>$row['id'], 'name'=>$row['name']); echo json_encode_cyr($json_result); break; case 'autocomplete_rubrik': $_GET['term'] = iconv("UTF-8", "WINDOWS-1251", $_GET['term']); $_GET['term'] = preg_replace("/[ ]+/", " ", trim($_GET['term'])); $_GET['term'] = mysql_real_escape_string($_GET['term']); $result = fetchAll( "SELECT * FROM `otrasl2` WHERE name_otrsl like '{$_GET['term']}%' and is_disabled='0' ORDER BY name_otrsl" ); foreach ( $result as $row ) $json_result[] = array('id'=>$row['id'], 'value'=>iconv('windows-1251','utf-8',$row['name_otrsl']), 'label'=>iconv('windows-1251','utf-8',$row['name_otrsl'])); echo json_encode_cyr($json_result); break; case 'autocomplete_rubrik_tovar': $_GET['term'] = iconv("UTF-8", "WINDOWS-1251", $_GET['term']); $_GET['term'] = preg_replace("/[ ]+/", " ", trim($_GET['term'])); $_GET['term'] = mysql_real_escape_string($_GET['term']); $result = fetchAll( "SELECT * FROM `grtovar_new` WHERE is_disabled='0' and name like '{$_GET['term']}%' ORDER BY name" ); foreach ( $result as $row ) { $parent = $row; $parents_array = array(); $parents_array[] = iconv('windows-1251','utf-8',$parent['name']); while ( $parent['id_parent'] > 0 ) { $parent = sqlval("select id, name, id_parent from grtovar_new where id='".$parent['id_parent']."'"); $parents_array[] = iconv('windows-1251','utf-8',$parent['name']); } $json_result[] = array('id'=>$row['id'], 'value'=>iconv('windows-1251','utf-8',$row['name']), 'label'=>implode(' > ', array_reverse($parents_array))); } echo json_encode_cyr($json_result); break; case 'save_info': $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['client_info'] = mysql_real_escape_string(strip_tags($_POST['client_info'], '<p><a><strong><em><u><ol><ul><li><table></table><tbody></tbody><thead></thead><tr></tr><td></td><th></th>')); $max_keywords = 2; if (is_array($_POST['keyword'])) { $_POST['keyword'] = array_filter($_POST['keyword'], 'strlen'); array_walk($_POST['keyword'], 'array_strip_tags'); array_walk($_POST['keyword'], 'array_first_keyword'); array_walk($_POST['keyword'], 'array_trim'); array_walk($_POST['keyword'], 'array_mysql_real_escape_string'); $keywords = implode(', ', $_POST['keyword']); } else { $keywords = ''; } $sql_logo = ''; if ($_POST['del_logo'] == 1) { $rs_old_logo = sqlval("select client_logo from firma where id='{$_POST['id_firm']}'"); if ($rs_old_logo['client_logo'] != '') { if (file_exists($base_url . $rs_old_logo['client_logo'])) { unlink($base_url . $rs_old_logo['client_logo']); $sql_logo = ", client_logo=''"; } } } if ($_FILES['logo']['tmp_name'] != '') { if (is_uploaded_file($_FILES['logo']['tmp_name'])) { $rs_old_logo = sqlval("select client_logo from firma where id='{$_POST['id_firm']}'"); if ($rs_old_logo['client_logo'] != '') { if (file_exists($base_url . $rs_old_logo['client_logo'])) unlink($base_url . $rs_old_logo['client_logo']); } $img_index = upload_foto($_FILES['logo']['tmp_name'], 200, 200, 0, 1, $base_url . "user_foto/company/logo"); $logo = "user_foto/company/logo/" . $img_index; $sql_logo = ", client_logo='{$logo}'"; } } sql("update firma set keyword='{$keywords}', client_info='{$_POST['client_info']}' {$sql_logo} where id='{$_POST['id_firm']}' limit 1"); firm_indexator($_POST['id_firm'], $l); header("Location: firma_info.php?id_firm={$_POST['id_firm']}"); break; case 'add_photo': if ( $_POST['id_firm'] != '' ) { if ($_FILES['photo']['tmp_name'] != '') { if (is_uploaded_file($_FILES['photo']['tmp_name'])) { $img_index = upload_foto($_FILES['photo']['tmp_name'], 190, 800, 1, 1, $base_url . "user_foto/company/photo"); $photo = "user_foto/company/photo/" . $img_index; } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("insert into firma_photo values(NULL, '{$_POST['id_firm']}', '{$photo}', '{$_POST['name']}')"); header("Location: firma_photo.php?id_firm={$_POST['id_firm']}"); } break; case 'edit_photo': if ( $_POST['id_firm'] != '' && $_POST['id_photo'] ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['id_photo'] = (int) $_POST['id_photo']; $sql_photo = ''; if ($_FILES['photo']['tmp_name'] != '') { if (is_uploaded_file($_FILES['photo']['tmp_name'])) { $rs_old_photo = sqlval("select * from firma_photo where id='{$_POST['id_photo']}' and firma_id='{$_POST['id_firm']}'"); if ($rs_old_photo['photo'] != '') { if (file_exists($base_url . $rs_old_photo['photo'])) unlink($base_url . $rs_old_photo['photo']); if (file_exists($base_url . str_replace('.','_sm.',$rs_old_photo['photo']))) unlink($base_url . str_replace('.','_sm.',$rs_old_photo['photo'])); } $img_index = upload_foto($_FILES['photo']['tmp_name'], 190, 800, 1, 1, $base_url . "user_foto/company/photo"); $photo = "user_foto/company/photo/" . $img_index; $sql_photo = ", photo='{$photo}'"; } } $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("update firma_photo set name='{$_POST['name']}' {$sql_photo} where id='{$_POST['id_photo']}' and firma_id='{$_POST['id_firm']}' limit 1"); header("Location: firma_photo.php?id_firm={$_POST['id_firm']}"); } break; case 'delete_photo': if ( $_GET['id_firm'] != '' && $_GET['id_photo'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['id_photo'] = (int) $_GET['id_photo']; $rs_old_photo = sqlval("select * from firma_photo where id='{$_GET['id_photo']}' and firma_id='{$_GET['id_firm']}'"); if ($rs_old_photo['photo'] != '') { if (file_exists($base_url . $rs_old_photo['photo'])) unlink($base_url . $rs_old_photo['photo']); if (file_exists($base_url . str_replace('.','_sm.',$rs_old_photo['photo']))) unlink($base_url . str_replace('.','_sm.',$rs_old_photo['photo'])); } sql("delete from firma_photo where id='{$_GET['id_photo']}' and firma_id='{$_GET['id_firm']}' limit 1"); header("Location: firma_photo.php?id_firm={$_GET['id_firm']}"); } break; case 'delete_many_photo': if((int)$_GET['firma_id']>0 and $_GET['set']){ $id_firm = (int)$_GET['firma_id']; $set = mysql_real_escape_string($_GET['set']); $old_fotos = fetchAll("select * from firma_photo where id in ($set) and firma_id='{$id_firm}'"); foreach($old_fotos as $rs_old_photo){ if ($rs_old_photo['photo'] != '') { if (file_exists($base_url . $rs_old_photo['photo'])) unlink($base_url . $rs_old_photo['photo']); if (file_exists($base_url . str_replace('.','_sm.',$rs_old_photo['photo']))) unlink($base_url . str_replace('.','_sm.',$rs_old_photo['photo'])); } } sql("delete from firma_photo where id in ($set) and firma_id='{$id_firm}'"); } break; case 'mass_add': $_POST['id_firma'] = intval( $_POST['id_firma']); //upload image if ($_FILES['img_foto']['tmp_name'] != '' ) { if (is_uploaded_file($_FILES['img_foto']['tmp_name'])) { $img_index=upload_foto($_FILES['img_foto']['tmp_name'],190,800,1,1,$base_url."user_foto/company/photo"); $img_index="user_foto/company/photo/" . $img_index; } } $result = sql("insert into firma_photo values(NULL, '{$_POST['id_firma']}', '{$img_index}', '')"); if (!$result) { error(); } break; case 'add_file': if ( $_POST['id_firm'] != '' ) { if ($_FILES['file']['tmp_name'] != '') { if (is_uploaded_file($_FILES['file']['tmp_name'])) { $path_parts = pathinfo($_FILES['file']['name']); $filename = md5(microtime()).'.'.$path_parts['extension']; move_uploaded_file($_FILES['file']['tmp_name'], $base_url . "user_foto/company/files/{$filename}"); $file = "user_foto/company/files/{$filename}"; } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("insert into firma_file values(NULL, '{$_POST['id_firm']}', '{$file}', '{$_POST['name']}')"); header("Location: firma_file.php?id_firm={$_POST['id_firm']}"); } break; case 'edit_file': if ( $_POST['id_firm'] != '' && $_POST['id_file'] ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['id_file'] = (int) $_POST['id_file']; $sql_file = ''; if ($_FILES['file']['tmp_name'] != '') { if (is_uploaded_file($_FILES['file']['tmp_name'])) { $rs_old_file = sqlval("select * from firma_file where id='{$_POST['id_file']}' and firma_id='{$_POST['id_firm']}'"); if ($rs_old_file['file'] != '') { if (file_exists($base_url . $rs_old_file['file'])) unlink($base_url . $rs_old_file['file']); } $path_parts = pathinfo($_FILES['file']['name']); $filename = md5(microtime()).'.'.$path_parts['extension']; move_uploaded_file($_FILES['file']['tmp_name'], $base_url . "user_foto/company/files/{$filename}"); $file = "user_foto/company/files/{$filename}"; $sql_file = ", file='{$file}'"; } } $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("update firma_file set name='{$_POST['name']}' {$sql_file} where id='{$_POST['id_file']}' and firma_id='{$_POST['id_firm']}' limit 1"); header("Location: firma_file.php?id_firm={$_POST['id_firm']}"); } break; case 'delete_file': if ( $_GET['id_firm'] != '' && $_GET['id_file'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['id_file'] = (int) $_GET['id_file']; $rs_old_file = sqlval("select * from firma_file where id='{$_GET['id_file']}' and firma_id='{$_GET['id_firm']}'"); if ($rs_old_file['file'] != '') { if (file_exists($base_url . $rs_old_file['file'])) unlink($base_url . $rs_old_file['file']); } sql("delete from firma_file where id='{$_GET['id_file']}' and firma_id='{$_GET['id_firm']}' limit 1"); header("Location: firma_file.php?id_firm={$_GET['id_firm']}"); } break; case 'add_video': if ( $_POST['id_firm'] != '' ) { if ($_FILES['video']['tmp_name'] != '') { if (is_uploaded_file($_FILES['video']['tmp_name'])) { $path_parts = pathinfo($_FILES['video']['name']); $videoname = md5(microtime()).'.'.$path_parts['extension']; move_uploaded_file($_FILES['video']['tmp_name'], $base_url . "user_foto/company/video/{$videoname}"); $video = $videoname; } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("insert into firma_video values(NULL, '{$_POST['id_firm']}', '{$video}', '', '0', NOW(), '0', '{$_POST['name']}', '1')"); header("Location: firma_video.php?id_firm={$_POST['id_firm']}"); } break; case 'edit_video': if ( $_POST['id_firm'] != '' && $_POST['id_video'] ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['id_video'] = (int) $_POST['id_video']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); sql("update firma_video set name='{$_POST['name']}' where id='{$_POST['id_video']}' and firma_id='{$_POST['id_firm']}' limit 1"); header("Location: firma_video.php?id_firm={$_POST['id_firm']}"); } break; case 'delete_video': if ( $_GET['id_firm'] != '' && $_GET['id_video'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['id_video'] = (int) $_GET['id_video']; $rs_old_video = sqlval("select * from firma_video where id='{$_GET['id_video']}' and firma_id='{$_GET['id_firm']}'"); if ($rs_old_video['converted_file'] != '') { if (file_exists($base_url . 'user_foto/company/video/flv/' . $rs_old_video['converted_file'])) unlink($base_url . 'user_foto/company/video/flv/' . $rs_old_video['converted_file']); $path_parts = pathinfo($rs_old_video['converted_file']); if (file_exists($base_url . 'user_foto/company/video/screenshot/' . $path_parts['filename'] . '_sm.jpg')) unlink($base_url . 'user_foto/company/video/screenshot/' . $path_parts['filename'] . '_sm.jpg'); if (file_exists($base_url . 'user_foto/company/video/screenshot/' . $path_parts['filename'] . '.jpg')) unlink($base_url . 'user_foto/company/video/screenshot/' . $path_parts['filename'] . '.jpg'); } sql("delete from firma_video where id='{$_GET['id_video']}' and firma_id='{$_GET['id_firm']}' limit 1"); header("Location: firma_video.php?id_firm={$_GET['id_firm']}"); } break; case 'add_news': if ( $_POST['id_firm'] != '' ) { if ($_FILES['img_foto']['tmp_name'] != '') { if (is_uploaded_file($_FILES['img_foto']['tmp_name'])) { $img_index = upload_foto_tovar($_FILES['img_foto']['tmp_name'],100,72,0,1,$base_url."user_foto/news"); $photo = "user_foto/news/" . $img_index; } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['news_header'] = mysql_real_escape_string(strip_tags($_POST['news_header'])); $_POST['news_short'] = mysql_real_escape_string(strip_tags($_POST['news_short'])); $_POST['news_full'] = mysql_real_escape_string(strip_tags($_POST['news_full'], '<p><a><strong><em><u><ol><ul><li>')); $rs_firma = sqlval("select name from firma where id='{$_POST['id_firm']}'"); $source = "<a href=\"/firma.php?id={$_POST['id_firm']}\" target=\"_blank\">{$rs_firma['name']}</a>"; $source = mysql_real_escape_string($source); sql("insert into news set news_header='{$_POST['news_header']}', news_short='{$_POST['news_short']}', news_full='{$_POST['news_full']}', src='{$source}', firma_id='{$_POST['id_firm']}', status='3', razdel='25', id_rubrik='6', data=NOW(), img_index='{$photo}', pokaz_img='1'"); header("Location: firma_news.php?id_firm={$_POST['id_firm']}"); } break; case 'edit_news': if ( $_POST['id_firm'] != '' && $_POST['id_news'] ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['id_news'] = (int) $_POST['id_news']; $sql_photo = ''; if ($_POST['del_photo'] == 1) { $rs_old_photo = sqlval("select * from news where id='{$_POST['id_news']}' and firma_id='{$_POST['id_firm']}'"); if ($rs_old_photo['img_index'] != '') { if (file_exists($base_url . $rs_old_photo['img_index'])) unlink($base_url . $rs_old_photo['img_index']); $sql_photo = ", img_index=''"; } } if ($_FILES['img_foto']['tmp_name'] != '') { if (is_uploaded_file($_FILES['img_foto']['tmp_name'])) { $rs_old_photo = sqlval("select * from news where id='{$_POST['id_news']}' and firma_id='{$_POST['id_firm']}'"); if ($rs_old_photo['img_index'] != '') { if (file_exists($base_url . $rs_old_photo['img_index'])) unlink($base_url . $rs_old_photo['img_index']); } $img_index = upload_foto_tovar($_FILES['img_foto']['tmp_name'],100,72,0,1,$base_url."user_foto/news"); $photo = "user_foto/news/" . $img_index; $sql_photo = ", img_index='{$photo}'"; } } $_POST['news_header'] = mysql_real_escape_string(strip_tags($_POST['news_header'])); $_POST['news_short'] = mysql_real_escape_string(strip_tags($_POST['news_short'])); $_POST['news_full'] = mysql_real_escape_string(strip_tags($_POST['news_full'], '<p><a><strong><em><u><ol><ul><li>')); $rs_firma = sqlval("select name from firma where id='{$_POST['id_firm']}'"); $source = "<a href=\"/firma.php?id={$_POST['id_firm']}\" target=\"_blank\">{$rs_firma['name']}</a>"; $source = mysql_real_escape_string($source); sql("update news set news_header='{$_POST['news_header']}', news_short='{$_POST['news_short']}', news_full='{$_POST['news_full']}', src='{$source}' {$sql_photo} where id='{$_POST['id_news']}' and firma_id='{$_POST['id_firm']}' limit 1"); header("Location: firma_news.php?id_firm={$_POST['id_firm']}"); } break; case 'delete_news': if ( $_GET['id_firm'] != '' && $_GET['id_news'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['id_news'] = (int) $_GET['id_news']; $rs_old_photo = sqlval("select * from news where id='{$_GET['id_news']}' and firma_id='{$_GET['id_firm']}'"); if ($rs_old_photo['img_index'] != '') { if (file_exists($base_url . $rs_old_photo['img_index'])) unlink($base_url . $rs_old_photo['img_index']); } sql("delete from news where id='{$_GET['id_news']}' and firma_id='{$_GET['id_firm']}' limit 1"); header("Location: firma_news.php?id_firm={$_GET['id_firm']}"); } break; case 'add_product': if ( $_POST['id_firm'] != '' && $_POST['id_rubrik'] !='' ) { if ($_FILES['img_foto']['tmp_name'] != '') { if (is_uploaded_file($_FILES['img_foto']['tmp_name'])) { $img_index = upload_foto_tovar($_FILES['img_foto']['tmp_name'],100,500,1,1,$base_url."user_foto/tovar"); $photo = "user_foto/tovar/" . $img_index; $photo_sm = "user_foto/tovar/" . str_replace(".", "_sm.", $img_index); } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['pokaz_foto'] = (int) $_POST['pokaz_foto']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); $_POST['price'] = mysql_real_escape_string(strip_tags($_POST['price'])); $_POST['edin'] = mysql_real_escape_string(strip_tags($_POST['edin'])); $_POST['note'] = mysql_real_escape_string(strip_tags($_POST['note'], '<p><a><strong><em><u><ol><ul><li>')); $re = sql("insert into tovar set name='{$_POST['name']}', price_ot='{$_POST['price']}', edin='{$_POST['edin']}', note='{$_POST['note']}', pokaz_foto='{$_POST['pokaz_foto']}', foto_small='{$photo_sm}', foto='{$photo}', id_firm='{$_POST['id_firm']}', posiz='1000',display = 1"); $last_id = mysql_insert_id(); if($last_id > 0 and $re){sql("update tovar set id_bitrix = '{$last_id}' where id=$last_id and id_firm <> 10537 LIMIT 1");} //add anoter fotos for($i=0; $i<count($_FILES['img_foto_other']['name']); $i++) { //Get the temp file path $tmpFilePath = $_FILES['img_foto_other']['tmp_name'][$i]; if ($tmpFilePath != ""){ $img_index = upload_foto_tovar($tmpFilePath,100,500,1,1,$base_url."user_foto/tovar"); $photo = "user_foto/tovar/" . $img_index; $photo_sm = "user_foto/tovar/" . str_replace(".", "_sm.", $img_index); sql("insert into tovar_images SET tovar={$last_id}, name='{$photo}', name_sm='{$photo_sm}'"); } } sql("insert into rubrik_tovar values (NULL, '{$last_id}', '{$_POST['id_rubrik']}')"); _sph_indexator_product($last_id,$l); header("Location: firma_product.php?id_firm={$_POST['id_firm']}"); } break; case 'edit_product': if ( $_POST['id_firm'] != '' && $_POST['id_product'] !='' && $_POST['id_rubrik'] !='' ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['id_product'] = (int) $_POST['id_product']; $rez = fetchAll("select * from tovar_images where tovar=".$_POST['id_product']); foreach($rez as $pic) { $picname = 'tovarimage_'.$pic['id']; if ($_POST[$picname] =='1') { sql('delete from tovar_images where id='.$pic['id']); if (file_exists($base_url . $pic['name'])) { unlink($base_url . $pic['name']); } if (file_exists($base_url . $pic['name_sm'])) { unlink($base_url . $pic['name_sm']); } } } for($i=0; $i<count($_FILES['img_foto_other']['name']); $i++) { //Get the temp file path $tmpFilePath = $_FILES['img_foto_other']['tmp_name'][$i]; if ($tmpFilePath != ""){ $img_index = upload_foto_tovar($tmpFilePath,100,500,1,1,$base_url."user_foto/tovar"); $photo = "user_foto/tovar/" . $img_index; $photo_sm = "user_foto/tovar/" . str_replace(".", "_sm.", $img_index); sql("insert into tovar_images SET tovar={$_POST['id_product']}, name='{$photo}', name_sm='{$photo_sm}'"); } } $sql_photo = ''; if ($_POST['del_photo'] == 1) { $rs_old_photo = sqlval("select * from tovar where id='{$_POST['id_product']}' and id_firm='{$_POST['id_firm']}'"); if ($rs_old_photo['foto'] != '') { if (file_exists($base_url . $rs_old_photo['foto'])) unlink($base_url . $rs_old_photo['foto']); } if ($rs_old_photo['foto_small'] != '') { if (file_exists($base_url . $rs_old_photo['foto_small'])) unlink($base_url . $rs_old_photo['foto_small']); } $sql_photo = ", foto='', foto_small=''"; } if ($_FILES['img_foto']['tmp_name'] != '') { if (is_uploaded_file($_FILES['img_foto']['tmp_name'])) { $rs_old_photo = sqlval("select * from tovar where id='{$_POST['id_product']}' and id_firm='{$_POST['id_firm']}'"); if ($rs_old_photo['foto'] != '') { if (file_exists($base_url . $rs_old_photo['foto'])) unlink($base_url . $rs_old_photo['foto']); } if ($rs_old_photo['foto_small'] != '') { if (file_exists($base_url . $rs_old_photo['foto_small'])) unlink($base_url . $rs_old_photo['foto_small']); } $img_index = upload_foto_tovar($_FILES['img_foto']['tmp_name'],100,500,1,1,$base_url."user_foto/tovar"); $photo_small = "user_foto/tovar/" . str_replace(".", "_sm.", $img_index); $photo = "user_foto/tovar/" . $img_index; $sql_photo = ", foto='{$photo}', foto_small='{$photo_small}'"; } } $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['pokaz_foto'] = (int) $_POST['pokaz_foto']; $_POST['id_rubrik'] = (int) $_POST['id_rubrik']; $_POST['name'] = mysql_real_escape_string(strip_tags($_POST['name'])); $_POST['price'] = mysql_real_escape_string(strip_tags($_POST['price'])); $_POST['edin'] = mysql_real_escape_string(strip_tags($_POST['edin'])); $_POST['note'] = mysql_real_escape_string(strip_tags($_POST['note'], '<p><a><strong><em><u><ol><ul><li>')); sql("update tovar set name='{$_POST['name']}', price_ot='{$_POST['price']}', edin='{$_POST['edin']}', note='{$_POST['note']}', pokaz_foto='{$_POST['pokaz_foto']}' {$sql_photo} where id='{$_POST['id_product']}' and id_firm='{$_POST['id_firm']}' limit 1"); sql("delete from rubrik_tovar where id_tovar='{$_POST['id_product']}' and id_rubrik='{$_POST['id_rubrik']}' limit 1"); sql("insert into rubrik_tovar values (NULL, '{$_POST['id_product']}', '{$_POST['id_rubrik']}')"); _sph_indexator_product($_POST['id_product'],$l); header("Location: firma_product.php?id_firm={$_POST['id_firm']}"); } break; case 'delete_product': if ( $_GET['id_firm'] != '' && $_GET['id_product'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['id_product'] = (int) $_GET['id_product']; $rs_old_photo = sqlval("select * from tovar where id='{$_GET['id_product']}' and id_firm='{$_GET['id_firm']}'"); if ($rs_old_photo['foto_small'] != '') { if (file_exists($base_url . $rs_old_photo['foto_small'])) unlink($base_url . $rs_old_photo['foto_small']); } if ($rs_old_photo['foto'] != '') { if (file_exists($base_url . $rs_old_photo['foto'])) unlink($base_url . $rs_old_photo['foto']); } sql("delete from tovar where id='{$_GET['id_product']}' and id_firm='{$_GET['id_firm']}' limit 1"); sql("delete from rubrik_tovar where id_tovar='{$_GET['id_product']}' limit 1"); header("Location: firma_product.php?id_firm={$_GET['id_firm']}"); } break; case 'delete_many_product': if ( $_GET['id_firm'] != '' && $_GET['set'] ) { $_GET['id_firm'] = (int) $_GET['id_firm']; $_GET['set'] = mysql_real_escape_string($_GET['set']); $all = fetchAll("select * from tovar where id in ({$_GET['set']}) and id_firm='{$_GET['id_firm']}'"); foreach($all as $rs_old_photo){ if ($rs_old_photo['foto_small'] != '') { if (file_exists($base_url . $rs_old_photo['foto_small'])) unlink($base_url . $rs_old_photo['foto_small']); } if ($rs_old_photo['foto'] != '') { if (file_exists($base_url . $rs_old_photo['foto'])) unlink($base_url . $rs_old_photo['foto']); } } sql("delete from tovar where id in ({$_GET['set']}) and id_firm='{$_GET['id_firm']}'"); sql("delete from rubrik_tovar where id_tovar in ({$_GET['set']})"); header("Location: firma_product.php?id_firm={$_GET['id_firm']}"); } break; case 'change_comments': if ( $_POST['id_firm'] != '' ) { $_POST['id_firm'] = (int) $_POST['id_firm']; if (isset($_POST['show'])) { foreach ($_POST['comment_id'] as $comment_id) { $comment_id = (int) $comment_id; sql("update firma_otzyv set hidden='0' where id='{$comment_id}' and id_firm='{$_POST['id_firm']}' limit 1"); } } elseif ($_POST['hide']) { foreach ($_POST['comment_id'] as $comment_id) { $comment_id = (int) $comment_id; sql("update firma_otzyv set hidden='1' where id='{$comment_id}' and id_firm='{$_POST['id_firm']}' limit 1"); } } header("Location: firma_comment.php?id_firm={$_POST['id_firm']}"); } break; case 'save_contacts': if ( $_POST['id_firm'] != '' ) { $_POST['id_firm'] = (int) $_POST['id_firm']; $_POST['name'] = mysql_real_escape_string( strip_tags(trim($_POST['name'])) ); $_POST['street'] = mysql_real_escape_string( strip_tags(trim($_POST['street'])) ); $_POST['house'] = mysql_real_escape_string( strip_tags(trim($_POST['house'])) ); $_POST['house_add'] = mysql_real_escape_string( strip_tags(trim($_POST['house_add'])) ); $_POST['corps'] = mysql_real_escape_string( strip_tags(trim($_POST['corps'])) ); $_POST['build'] = mysql_real_escape_string( strip_tags(trim($_POST['build'])) ); $_POST['address-add'] = mysql_real_escape_string( strip_tags(trim($_POST['address-add'])) ); $_POST['sub_adm_area_id'] = (int) $_POST['sub_adm_area_id']; $_POST['locality_id'] = (int) $_POST['locality_id']; sql("delete from rubrik2 where id_firm='{$_POST['id_firm']}'"); foreach ($_POST['rubrik_id'] as $rubrik) { $rubrik = (int) $rubrik; if ($rubrik > 0) { $r_ins_rubr=sql("insert into rubrik2 values (null, '{$_POST['id_firm']}', '{$rubrik}')"); if (!$r_ins_rubr) error(); } } sql("delete from firma_site where id_firma = '{$_POST['id_firm']}'"); foreach ( $_POST['url'] as $url ) { $url = mysql_real_escape_string( strip_tags(trim($url)) ); if ($url != '') sql("insert into firma_site values (NULL, '{$_POST['id_firm']}', '{$url}')"); } sql("delete from firma_email where id_firma = '{$_POST['id_firm']}'"); foreach ( $_POST['email'] as $email ) { $email = mysql_real_escape_string( strip_tags(trim($email)) ); if ($email != '') sql("insert into firma_email values (NULL, '{$_POST['id_firm']}', '{$email}')"); } sql("delete from firma_phone where id_firma='{$_POST['id_firm']}'"); for ($i = 1; $i <= count($_POST['phones_country_code']); $i++) { if ($_POST['phones_country_code'][$i] != '') { $phone = '+' . $_POST['phones_country_code'][$i] . ' (' . $_POST['phones_city_code'][$i] . ') ' . preg_replace('/([0-9]+)([0-9]{2})([0-9]{2})/', "\\1-\\2-\\3", $_POST['phones_phone_number'][$i]); $phone = mysql_real_escape_string($phone); $_POST['phones_ext_phone'][$i] = mysql_real_escape_string($_POST['phones_ext_phone'][$i]); $_POST['phones_info'][$i] = mysql_real_escape_string($_POST['phones_info'][$i]); sql("insert into firma_phone values (NULL, '{$_POST['id_firm']}', '{$phone}', '{$_POST['phones_ext_phone'][$i]}', '{$_POST['phones_info'][$i]}', '1')"); } } sql("update firma set name='{$_POST['name']}', street='{$_POST['street']}', house='{$_POST['house']}', house_add='{$_POST['house_add']}', corps='{$_POST['corps']}', build='{$_POST['build']}', address_add='{$_POST['address_add']}', locality_id='{$_POST['locality_id']}', sub_adm_area_id='{$_POST['sub_adm_area_id']}' where id='{$_POST['id_firm']}'"); firm_indexator($_POST['id_firm'], $l); header("Location: firma_contact.php?id_firm={$_POST['id_firm']}"); } break; case 'vote_do': $result = array(); $result['status'] = 0; if ( $_POST['id'] != '' && $_POST['value'] != '' ) { $_POST['id'] = (int) $_POST['id']; $_POST['value'] = (int) $_POST['value']; if ($_POST['value'] < 1) $_POST['value'] = 1; if ($_POST['value'] > 5) $_POST['value'] = 5; $rs_company = sqlval("select id from firma where id='{$_POST['id']}'"); if ($rs_company['id'] > 0) { $ip=$_SERVER['REMOTE_ADDR']; $ip2=getIp(); $uagent=$_SERVER['HTTP_USER_AGENT']; $uinmd=md5($ip.$ip2.$uagent); $sid = $_REQUEST['sid']; $rs_is_voted=sqlval("SELECT COUNT(*) FROM `firma_rate_stat` WHERE `firma_id` = '{$_POST['id']}' AND (`sid`='{$sid}' OR (`ipUser`='{$ip}' AND `ipProxy`='{$ip2}' AND ((UNIX_TIMESTAMP() - UNIX_TIMESTAMP(`date`)) < 60)))"); if ($rs_is_voted[0] == 0) { $r_ins = sql("INSERT INTO `firma_rate_stat` (`firma_id`, `sid`, `uinmd`, `ipUser`, `ipProxy`) VALUES ('{$_POST['id']}', '{$sid}', '{$uinmd}', '{$ip}', '{$ip2}')"); if ($r_ins) { $rs_rate_exists = sqlval("select firma_id from firma_rate where firma_id='{$_POST['id']}'"); if ($rs_rate_exists['firma_id'] > 0) sql("update firma_rate set voters=voters+1, rate=rate+{$_POST['value']} where firma_id='{$_POST['id']}'"); else sql("insert into firma_rate values('{$_POST['id']}', 1, '{$_POST['value']}')"); $result['status'] = 1; $result['rate'] = getCompanyCurrenRating($_POST['id']); } } } } echo json_encode($result); break; } ?>
/firma/
Имя
Дата
Размер
..
2026-10-02
ckeditor
2015-11-03
images
2015-04-04
inc
2020-04-06
js
2015-12-02
swf
2014-10-30
JSON.php
2010-05-13
1 кб.
action.php
2016-01-19
35 кб.
action_restoran.php
2013-02-05
1 кб.
application.js
2012-07-06
2 кб.
bottom_firma.inc
2011-10-28
446 байт
bottom_firma.inc.php
2011-10-28
456 байт
comments_act.php
2013-12-17
1 кб.
comments_action.php
2013-12-17
449 байт
delete_news.php
2023-12-21
650 байт
delete_news.php~
2017-03-20
579 байт
firma_comment.php
2017-09-04
4 кб.
firma_comment_rss.php
2017-06-22
2 кб.
firma_contact.php
2017-03-09
21 кб.
firma_delete_product.php
2020-04-06
438 байт
firma_edit_delivery.php
2020-04-06
480 байт
firma_edit_news.php
2023-12-21
2 кб.
firma_edit_news.php~
2019-01-22
2 кб.
firma_edit_product.php
2020-04-06
1 кб.
firma_file.php
2017-04-04
7 кб.
firma_info.php
2017-03-24
1 кб.
firma_my.php
2017-03-06
497 байт
firma_news.php
2020-04-17
945 байт
firma_photo.php
2019-08-12
3 кб.
firma_product.php
2020-04-06
15 кб.
firma_profile.inc.php
2011-12-26
1 кб.
firma_slider.php
2019-08-13
3 кб.
firma_stat.inc.php
2013-08-30
518 байт
firma_stat.php
2013-08-30
6 кб.
firma_statistic.php
2019-04-01
7 кб.
firma_statistic_back.php
2019-03-28
5 кб.
firma_video.php
2012-09-25
6 кб.
index.php
2021-01-14
22 кб.
restoran_comment.php
2015-09-29
9 кб.
restoran_my.php
2014-11-26
1 кб.
restoran_stat.php
2014-11-26
3 кб.
sprav.php
2017-03-09
627 байт
style.css
2011-11-07
8 кб.
upload.php
2015-11-03
609 байт
/firma
Загрузить файлы
Файл 1
Файл 2
Файл 3