}else{?> }else{?> include "../../dbcon.inc"; $day = date('Ymdhis'); $save_dir="../gallery"; $isUploaded=FALSE; $upload_file=$ph; $upload_alt=$ph_alt; if(!strcmp($upload_file,"none")){ continue; }else{ $upload_file_name=$ph_name; $upload_file_size=$ph_size; $upload_file_type=$ph_type; if ( $upload_file_size >= (150*1024)){ ?> }else{ $filename=explode(".",$upload_file_name); $extension=$filename[sizeof($filename)-1]; $rfilename=$day.".".$extension; if(!strcmp($extension,"php")||!strcmp($extension,"phtml")||!strcmp($extension,"inc")||!strcmp($extension,"txt")||!strcmp($extension,"asp")) { continue; } $dest=$save_dir."/".$rfilename; if ($upload_file_name!=""){ copy($upload_file,$dest); $ph_name=$rfilename; } $isUploaded=TRUE; } } $ip=getenv('REMOTE_ADDR'); $title=addslashes($title); $content=addslashes($content); $query="insert into $tname(title,content,name,writeday,readnum,ip,ph,ph_alt) values('$title','$content','$name','$day','0','$ip','$ph_name','$ph_alt')"; $result=mysql_query($query); echo(""); ?> }?> }?>