<?php
include 'db.php';
include 'config.php';
$sendto = 'Chris'; #put your username here
function showguestform(){
?>
<form method="post" action="">
Name: <input type="text" name="guestname" value="<?php echo htmlentities($_POST['guestname']); ?>" /><br />
Email: <input type="text" name="guestemail" value="<?php echo htmlentities($_POST['guestemail']); ?>" /><br />
Message: <textarea name="guestmessage"><?php echo htmlentities($_POST['guestmessage']); ?></textarea><br />
Security key: <input type="text" id="key" name="key"><img src="news/image.php" /><br />
<input type="submit" name="guests1" value="Send message" />
</form>
<?php
}
if(!$_POST['guests1']){
showguestform();
}else{
if(md5($_POST['key'] !== $_SESSION['image_random_value'])){
echo "Please enter the security key<br />";
showguestform();
}elseif(!$_POST['guestname']){
echo "Please enter your name<br />";
showguestform();
}elseif(!$_POST['guestemail']){
echo "Please enter your email address<br />";
showguestform();
}elseif(!$_POST['guestmessage']){
echo "Please enter a message<br />";
showguestform();
}else{
$guestid = getresult("SELECT uid FROM $newsusers WHERE user = 'Guest'");
$title = "New message from " . slash2($_POST['guestname']);
$message = "Email address: " . slash2($_POST['guestemail']) . "\n\r\n\r" . slash2($_POST['guestmessage']);
$sentfrom = $guestid;
$sentto = getresult("SELECT uid FROM $newsusers WHERE user = '$sendto'");
$viewed = 1;
$posted = time();
$sql = "INSERT INTO $newsprivate (title,message,sentfrom,sentto,viewed,posted) VALUES ('$title','$message','$sentfrom','$sentto','$viewed','$posted')";
$query = mysql_query($sql) or die(mysql_error());
echo "Your message has been sent";
}
}
?>
<?php
session_start();
include 'db.php';
include 'config.php';
$sendto = 'Chris'; #put your username here
function showguestform(){
?>
<form method="post" action="">
Name: <input type="text" name="guestname" value="<?php echo htmlentities($_POST['guestname']); ?>" /><br />
Email: <input type="text" name="guestemail" value="<?php echo htmlentities($_POST['guestemail']); ?>" /><br />
Message: <textarea name="guestmessage"><?php echo htmlentities($_POST['guestmessage']); ?></textarea><br />
Security key: <input type="text" id="key" name="key"><img src="image.php" /><br />
<input type="submit" name="guests1" value="Send message" />
</form>
<?php
}
if(!$_POST['guests1']){
showguestform();
}else{
if(md5($_POST['key']) !== $_SESSION['image_random_value']){
echo "Please enter the security key<br />";
showguestform();
}elseif(!$_POST['guestname']){
echo "Please enter your name<br />";
showguestform();
}elseif(!$_POST['guestemail']){
echo "Please enter your email address<br />";
showguestform();
}elseif(!$_POST['guestmessage']){
echo "Please enter a message<br />";
showguestform();
}else{
$guestid = getresult("SELECT uid FROM $newsusers WHERE user = 'Guest'");
$title = "New message from " . slash2($_POST['guestname']);
$message = "Email address: " . slash2($_POST['guestemail']) . "\n\r\n\r" . slash2($_POST['guestmessage']);
$sentfrom = $guestid;
$sentto = getresult("SELECT uid FROM $newsusers WHERE user = '$sendto'");
$viewed = 1;
$posted = time();
$sql = "INSERT INTO $newsprivate (title,message,sentfrom,sentto,viewed,posted) VALUES ('$title','$message','$sentfrom','$sentto','$viewed','$posted')";
$query = mysql_query($sql) or die(mysql_error());
echo "Your message has been sent";
}
}
?>