include "../cdbcon.inc";
if (!$sess_name){?>
}else{?>
}else{?>
}else{?>
$save_dir="../../".$home."/gallery";
$isUploaded=FALSE;
$upload_file=$ph;
$upload_alt=$ph_alt;
if(!strcmp($upload_file,"none")){
continue;
}else{
$upload_file_name=$ph_name;
$upload_file_size=$ph_size;
$upload_file_type=$ph_type;
if ( $upload_file_size >= (150*1024)){
?>
}else{
$filename=explode(".",$upload_file_name);
$extension=$filename[sizeof($filename)-1];
if(!strcmp($extension,"php")||!strcmp($extension,"phtml")||!strcmp($extension,"inc")||!strcmp($extension,"txt")||!strcmp($extension,"asp"))
{
continue;
}
$dest=$save_dir."/".$upload_file_name;
if ($upload_file_name!=""){
copy($upload_file,$dest);
}
$isUploaded=TRUE;
}
}
$ip=getenv('REMOTE_ADDR');
$title=addslashes($title);
$content=addslashes($content);
$day = date('Ymdhis');
$query="insert into $tname(title,content,name,writeday,readnum,ip,ph,ph_alt) values('$title','$content','$name','$day','0','$ip','$ph_name','$ph_alt')";
$result=mysql_query($query);
echo("");
?>
}?>
}?>
}?>