alert('ºñ¹Ð¹øÈ£°¡ ÀÏÄ¡ÇÏÁö ¾Ê½À´Ï´Ù.'); history.back(-1); "; exit; } }#top_if else{ include $board_base."zboard_add.html"; } break; case("write") : #------- ³Ñ¾îº» º¯¼ö °ª ÇÊÅ͸µ $subject=trim($subject); /* $subject=addslashes($subject); $body=addslashes($body); $email=addslashes($email); $home_page=addslashes($home_page); */ $name=str_replace(" ","",$name); $name=trim($name); #$name=addslashes($name); $pwd=base64_encode($pwd); $reg_date=date("Y-m-d"); $ip=$REMOTE_ADDR; $date_num=date("Ymd"); $zb_upload_name=trim($zb_upload_name); $file_chk=explode(".",$zb_upload_name); if(trim($file_chk[count($file_chk)-1]=="php" or $file_chk[count($file_chk)-1]=="php4" or $file_chk[count($file_chk)-1]=="phtml" or $file_chk[count($file_chk)-1]=="php3" or $file_chk[count($file_chk)-1]=="inc" or $file_chk[count($file_chk)-1]=="html")){ echo" "; exit; } if($zb_upload_name){ if(!file_exists($zb_upload)){ echo " "; } else{ if(file_exists($board_upload_base."$board/$zb_upload_name")){ while(file_exists($board_upload_base."$board/$zb_upload_name")){ $zb_upload_name="a".$zb_upload_name; }#while }#if $up_filename=$zb_upload; $up_filename=$zb_upload_name; copy($zb_upload,$board_upload_base."$board/$zb_upload_name"); unlink($zb_upload); }#else }#if $query="insert into $board (subject,name,email,pwd,body,home_page,reg_date,ip,r_num,type,up_filename,pic_location,n_type,date_num) values ('$subject','$name','$email','$pwd','$body','$home_page','$reg_date','$ip',0,'$type','$up_filename','$pic_location','$n_type','$date_num')"; $write_board=mysql_query($query); query_chk($write_board,"board write error"); $query="select id from $board order by id DESC LIMIT 1"; $board_id_select=mysql_query($query); query_chk($board_id_select,"board_id_select error"); $board_id=mysql_fetch_array($board_id_select); $parent_id=$board_id[id]; $sort=$parent_id; $query="update $board set parent_id='$parent_id', sort='$sort' where id='$board_id[id]'"; $board_update=mysql_query($query); query_chk($board_update,"board update error"); print ""; exit; break; case("reply_write") : #------- ³Ñ¾îº» º¯¼ö °ª ÇÊÅ͸µ $subject=trim($subject); /* $subject=addslashes($subject); $body=addslashes($body); $email=addslashes($email); $home_page=addslashes($home_page); */ $name=str_replace(" ","",$name); $name=trim($name); #$name=addslashes($name); $pwd=base64_encode($pwd); $reg_date=date("Y-m-d"); $ip=$REMOTE_ADDR; $zb_upload_name=trim($zb_upload_name); if($zb_upload_name){ if(!file_exists($zb_upload)){ echo " "; } else{ if(file_exists($board_upload_base."$board/$zb_upload_name")){ while(file_exists($board_upload_base."$board/$zb_upload_name")){ $zb_upload_name="a".$zb_upload_name; }#while }#if $up_filename=$zb_upload; $up_filename=$zb_upload_name; copy($zb_upload,$board_upload_base."$board/$zb_upload_name"); unlink($zb_upload); }#else } $query="insert into $board (subject,name,email,pwd,body,home_page,reg_date,ip,r_num,type,up_filename,parent_id) values ('$subject','$name','$email','$pwd','$body','$home_page','$reg_date','$ip',0,'$type','$up_filename','$parent_id')"; $reply_board=mysql_query($query); query_chk($reply_board,"board reply error"); $query="select id from $board order by id DESC LIMIT 1"; $reply_board_id_select=mysql_query($query); query_chk($reply_board_id_select,"reply_board_id_select error"); $reply_board_id=mysql_fetch_array($reply_board_id_select); $sort=$sort."-".$reply_board_id[id]; $query="update $board set parent_id='$parent_id',sort='$sort' where id='$reply_board_id[id]'"; $reply_board_update=mysql_query($query); query_chk($reply_board_update,"board reply update error"); print ""; exit; break; case("comment") : #------- ³Ñ¾îº» º¯¼ö °ª ÇÊÅ͸µ $subject=trim($subject); /* $subject=addslashes($subject); $body=addslashes($body); $email=addslashes($email); $home_page=addslashes($home_page); */ $name=str_replace(" ","",$name); $name=trim($name); #$name=addslashes($name); $pwd=base64_encode($pwd); $reg_date=date("Y-m-d"); $ip=$REMOTE_ADDR; $query="insert into $board set name='$name',pwd='$pwd',body='$body',reg_date='$reg_date',ip='$ip',parent_id='$id'"; #print "$query"; $reply_board=mysql_query($query); query_chk($reply_board,"board comment error"); print ""; exit; break; case("edit") : $query="select pwd from board_admin where board_id='$board_id'"; $admin_result=mysql_query($query); query_chk($admin_result,"admin_pwd error"); $admin=mysql_fetch_array($admin_result); $query="select pwd from $board where id='$id'"; $notic_result=mysql_query($query); query_chk($notic_result,"notic_pwd error"); $notic=mysql_fetch_array($notic_result); $pwd=base64_encode($pwd); if($pwd==$notic[pwd]){ $query="select id,subject,name,email,pwd,body,home_page,reg_date,ip,r_num,parent_id,type,up_filename,n_type,pic_location from $board where id='$id'"; $board_list=mysql_query("$query"); query_chk($board_list,"board_list_select_error from edit"); $list=mysql_fetch_array($board_list); $pwd=base64_decode($list[pwd]); if($list[type]=="text"){ $type_chk1="checked"; } else{ $type_chk2="checked"; } if($list[n_type]=="headline"){ $n_type_chk1="checked"; } else{ $n_type_chk2="checked"; } if($list[pic_location]=="left"){ $pic_chk1="checked"; } elseif($list[pic_location]=="right"){ $pic_chk2="checked"; } else{ $pic_chk3="checked"; } include $board_base."zboard_edit.html"; } else{ echo" "; exit; } break; case("update") : #------- ¼öÁ¤µÈ ±Û¿¡ ÆÄÀÏÀÌ ÀÖÀ¸¸é ±âÁ¸ÀÇ ÆÄÀÏÀ» »èÁ¦ÇÏ°í »õÆÄÀÏÀ» ¿Ã¸°´Ù. $zb_upload_name=trim($zb_upload_name); if($zb_upload_name){ if(!file_exists($zb_upload)){ echo " "; } else{ if(file_exists($board_upload_base."$board/$zb_upload_name")){ echo " "; } else{ $query="select up_filename from $board where id='$id'"; $up_file_qry=mysql_query($query); query_chk($up_file_qry,"up_file_qry_error from edit"); $up_file=mysql_fetch_array($up_file_qry); if($up_file[up_filename]){ unlink($board_upload_base."$board/$up_file[up_filename]"); } $up_filename=$zb_upload; $up_filename=$zb_upload_name; copy($zb_upload,$board_upload_base."$board/$zb_upload_name"); unlink($zb_upload); }#else }#else }#if else{ $query="select up_filename from $board where id='$id'"; $up_file_qry=mysql_query($query); query_chk($up_file_qry,"up_file_qry_error from edit"); $up_file=mysql_fetch_array($up_file_qry); $up_filename=$up_file[up_filename]; }#else #------- ³Ñ¾îº» º¯¼ö °ª ÇÊÅ͸µ $subject=trim($subject); /* $subject=addslashes($subject); $body=addslashes($body); $email=addslashes($email); $home_page=addslashes($home_page); */ $name=str_replace(" ","",$name); $name=trim($name); #$name=addslashes($name); $pwd=base64_encode($pwd); $query="update $board set subject='$subject',name='$name',email='$email',pwd='$pwd',body='$body',home_page='$home_page',type='$type' ,up_filename='$up_filename',n_type='$n_type',pic_location='$pic_location' where id='$id'"; $update_board=mysql_query($query); query_chk($update_board,"board update error"); print ""; exit; break; case("delete") : $board_id=ereg_replace("zboard","",$board); $query="select pwd from board_admin where board_id='$board_id'"; $admin_result=mysql_query($query); query_chk($admin_result,"admin_pwd error"); $admin=mysql_fetch_array($admin_result); $query="select * from $board where id='$id'"; $notic_result=mysql_query($query); query_chk($notic_result,"notic_pwd error"); $notic=mysql_fetch_array($notic_result); $pwd=base64_encode($pwd); if($pwd==$notic[pwd] or $pwd==$admin[pwd]){ $query="delete from $board where id='$id'"; $delete_user=mysql_query($query); query_chk($delete_user,"user delete error"); if($notic[up_filename]){ unlink($board_upload_base."$board/$notic[up_filename]"); } if($notic[subject]){ include $board_base."zboard_list.html"; } else{ $id=$notic[parent_id]; #include $board_base."zboard_view.html"; print ""; exit; } } else{ echo" "; } break; case("view") : include $board_base."zboard_view.html"; break; case("reply") : $query="select id,subject,body from $board where id='$id'"; $board_list=mysql_query("$query"); query_chk($board_list,"board_list_select_error from edit"); $list=mysql_fetch_array($board_list); $list[body]=":".$list[body]; $list[body]=str_replace("\n","\n:",$list[body]); $list[body]="\n\n".$list[body]; include $board_base."zboard_reply.html"; break; } #print $skin_exp[1]; ?>