0byt3m1n1-V2
Path:
/
home
/
bangtoey
/
domains
/
bangtoey.go.th
/
public_html
/
webboard
/
[
Home
]
File: post.php
<?php require_once("check_thai_ip.php"); if (!$___in_range) { header('HTTP/1.1 403 Forbidden'); echo "<h1>403 Forbidden</h1><p>ไม่อนุญาตให้เข้าถึงจาก IP ของคุณ: " . $_SERVER['REMOTE_ADDR'] . "</p>"; exit(); } ?> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html><!-- InstanceBegin template="/Templates/template_a.dwt.php" codeOutsideHTMLIsLocked="false" --> <head> <!-- InstanceBeginEditable name="doctitle" --> <!-- InstanceEndEditable --> <?php require_once('../admin/Connections/conndb.php'); mysql_select_db($database_conndb, $conndb); ?> <title>องค์การบริหารส่วนตำบลบางเตย ที่อยู่ 8/8 หมู่2 ตำบลบางเตย อำเภอเมืองฉะเชิงเทรา จังหวัดฉะเชิงเทรา 24000 ::www.bangtoey.go.th</title> <meta http-equiv="Content-Type" content="text/html; charset=windows-874"> <link href="../styles.css" rel="stylesheet" type="text/css"> <!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable --> <style type="text/css"> <!-- body { margin-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; background-color: #3CFFFF; } --> </style> <!--styles --> <link href="../styles.css" rel="stylesheet" type="text/css" /> <link href="../css/Hover%20Buttons.css" rel="stylesheet" type="text/css"/> <link href="../css/Hoverable-Sidenav.css" rel="stylesheet" type="text/css"/> <!--<script src="https://platform-api.sharethis.com/js/sharethis.js#property=5d255a83d97c100012d80679&product='inline-share-buttons' async='async" type='text/javascript'> --> </script> <!--styles --> <!--menutop hover --> <link href="../imagehover.css-master/css/demo-page.css" rel="stylesheet" media="all"> <link href="../imagehover.css-master/css/imagehover.min.css" rel="stylesheet" media="all"> <link rel='shortcut icon' type='image/x-icon' href='/favicon.ico' /> <!--end --> <style type="text/css"> <!-- a:link { text-decoration: none; } a:visited { text-decoration: none; } a:hover { text-decoration: none; } a:active { text-decoration: none; } .style6 {color: #FFFFFF} --> </style></head> <body background="../images/0bg1.png" style="background-repeat:no-repeat; background-position:top"> <!--<div id="mySidenav" class="sidenav"> <a href="http://new.huayyai.go.th/index.php" id="about"> </a> <a href="http://new.huayyai.go.th/news.php?cat_id=1" id="blog"> </a> <a href="http://new.huayyai.go.th/news.php?cat_id=4" id="projects"> </a> <a href="http://new.huayyai.go.th/albums/index.php" id="contact"> </a> </div> --> <!-- content --> <div align="center"> <table width="950" border="0" align="center" cellpadding="0" cellspacing="0"> <tr> <td align="center" valign="top"><tr> <td height="650" align="center" valign="top" background="../images/head-1.png" style="background-repeat:no-repeat"><table width="980" border="0" align="center" cellpadding="0" cellspacing="0"> <tr> <td height="515" align="center" valign="top"> </td> </tr> <tr> <td height="364" align="center" valign="top"><iframe src="/title_head.html" width="980" height="335" scrolling="no" frameborder="0" marginheight="0" marginwidth="0"></iframe></td> </tr> <tr> <td align="center" valign="top"><iframe src="/menu-top.html" width="980" height="53" scrolling="no" frameborder="0" marginheight="0" marginwidth="0"></iframe></td> </tr> <tr> <td height="150" align="center" valign="top"> </td> </tr> </table></td> </tr> </td> </tr> <tr> <td align="center" valign="top"><table width="980" border="0" align="center" cellpadding="0" cellspacing="0"> <tr> <td align="center" valign="top"> </td> </tr> <tr> <td align="center" valign="top"><!-- InstanceBeginEditable name="EditRegion3" --> <table width="98%" border="0" cellspacing="0" cellpadding="0"> <tr> <td> </td> </tr> <tr> <td><div align="center"> <? include("config.inc.php"); include("function.php"); // เช็คหมวดของเว็บบอร์ด mysql_connect($host,$user_db,$passwd_db); mysql_query ("SET NAMES 'tis620'"); $c_sql = "select * from webboard_category where cat_name='$Category' "; $c_result = mysql_db_query($dbname,$c_sql); $c_NRow = mysql_num_rows($c_result); $c_row = mysql_fetch_array($c_result); $nlist = $c_row["cat_title"]; if($c_NRow==0) { echo "<center><br>"; echo "<font color=red size=+1> กรุณาระบุ Category ให้ตรงกับที่ web เปิดใช้ด้วยครับ</font>"; echo "<br>"; echo "</center>"; exit(); } // จบการเช็ค if ($_SERVER['HTTP_CLIENT_IP']) { $IP = $_SERVER['HTTP_CLIENT_IP']; } elseif (ereg("[0-9]",$_SERVER["HTTP_X_FORWARDED_FOR"] )) { $IP = $_SERVER["HTTP_X_FORWARDED_FOR"]; } else { $IP = $_SERVER["REMOTE_ADDR"]; } $Member = 0; // ป้องกันการแทรก html กับ ละเครื่องหมาย ' " $QTitle = htmlspecialchars($QTitle, ENT_COMPAT, 'ISO-8859-1'); $QNote = htmlspecialchars($QNote, ENT_COMPAT, 'ISO-8859-1'); $QName = htmlspecialchars($QName, ENT_COMPAT, 'ISO-8859-1'); $QEmail = htmlspecialchars($QEmail, ENT_COMPAT, 'ISO-8859-1'); // ===== เพิ่มฟังก์ชันกรองคำต้องห้าม ===== function hasBadWords($text) { $badWords = array('พนัน', 'เว็บโป๊', 'เซ็กส์', 'บาคาร่า', 'หวย', 'คาสิโน','แทงบอล','บอล','วัว','ไก่','มวย','แทง', 'แทง', 'asd', 'โป๊', '18+', 'xxx', 'เสี่ยงโชค'); foreach ($badWords as $word) { if (stripos($text, $word) !== false) { return true; } } return false; } // เช็คหมวดของเว็บบอร์ด mysql_connect($host,$user_db,$passwd_db); mysql_query ("SET NAMES 'tis620'"); $c_sql = "select * from webboard_category where cat_name='$Category' "; $c_result = mysql_db_query($dbname,$c_sql); $c_NRow = mysql_num_rows($c_result); $c_row = mysql_fetch_array($c_result); $nlist = $c_row["cat_title"]; if($c_NRow==0) { echo "<center><br>"; echo "<font color=red size=+1> กรุณาระบุ Category ให้ตรงกับที่ web เปิดใช้ด้วยครับ</font>"; echo "<br>"; echo "</center>"; exit(); } // จบการเช็ค if ($_SERVER['HTTP_CLIENT_IP']) { $IP = $_SERVER['HTTP_CLIENT_IP']; } elseif (ereg("[0-9]",$_SERVER["HTTP_X_FORWARDED_FOR"] )) { $IP = $_SERVER["HTTP_X_FORWARDED_FOR"]; } else { $IP = $_SERVER["REMOTE_ADDR"]; } $Member = 0; // ป้องกันการแทรก html กับ ละเครื่องหมาย ' " $QTitle = htmlspecialchars($QTitle, ENT_COMPAT, 'ISO-8859-1'); $QNote = htmlspecialchars($QNote, ENT_COMPAT, 'ISO-8859-1'); $QName = htmlspecialchars($QName, ENT_COMPAT, 'ISO-8859-1'); $QEmail = htmlspecialchars($QEmail, ENT_COMPAT, 'ISO-8859-1'); // ===== ตรวจสอบคำต้องห้าม ก่อนดำเนินการต่อ ===== if (hasBadWords($QTitle) || hasBadWords($QNote)) { echo "<center><br><font color=red size=+1> ข้อความมีคำต้องห้าม เช่น การพนัน หรือคำไม่เหมาะสม กรุณาแก้ไขก่อนโพสต์</font><br>"; echo "<a href='javascript:history.back(1)' class='styles2'>[ กลับไปแก้ไข ]</a></center>"; exit(); } // ป้องกันคำหยาบ $QTitle = CheckRude($QTitle); $QNote = CheckRude($QNote); $QName = CheckRude($QName); $QEmail = CheckRude($QEmail); // ตรวจสอบการแทรกรูปภาพ $txt = array(":b1:", ":b2:",":b3:", ":b4:", ":b5:", ":b6:", ":b7:", ":b8:", ":b9:", ":b10:", ":b11:"); $pic = array("b1.gif","b2.gif","b3.gif","b4.gif","b5.gif","b6.gif","b7.gif","b8.gif","b9.gif","b10.gif","b11.gif"); for ($a=0 ; $a<sizeof($txt) ; $a++) { $QNote = eregi_replace($txt[$a],"<img src=\"pic/$pic[$a]\">",$QNote); } // ตรวจสอบว่า มีการป้อน url หรือ email มาหรือไม่ ถ้ามีให้ทำ link //สำหรับเปลี่ยนอักขระที่กำหนด ให้เป็นแทก html ต่างๆ $QNote = eregi_replace ( "\[b\]", "<b> " , $QNote ) ; $QNote = eregi_replace ( "\[/b\]", " </b>" , $QNote ) ; $QNote = eregi_replace ( "\[i\]", "<i> " , $QNote ) ; $QNote = eregi_replace ( "\[/i\]", " </i>" , $QNote ) ; $QNote = eregi_replace ( "\[u\]", "<u> " , $QNote ) ; $QNote = eregi_replace ( "\[sup\]", "<sup> " , $QNote ) ; $QNote = eregi_replace ( "\[/sup\]", " </sup>" , $QNote ) ; $QNote = eregi_replace ( "\[sub\]", "<sub> " , $QNote ) ; $QNote = eregi_replace ( "\[/sub\]", " </sub>" , $QNote ) ; $QNote = eregi_replace ( "\[/u\]", " </u>" , $QNote ) ; $QNote = eregi_replace ( "\[\-\-\-\]", " " , $QNote ) ; $QNote = eregi_replace ( "\[color=red\]", "<font color=red > " , $QNote ) ; $QNote = eregi_replace ( "\[color=green\]", "<font color=green> " , $QNote ) ; $QNote = eregi_replace ( "\[color=blue\]", "<font color=blue> " , $QNote ) ; $QNote = eregi_replace ( "\[color=orange\]", "<font color=FF6600> " , $QNote ) ; $QNote = eregi_replace ( "\[color=pink\]", "<font color=FF00FF> " , $QNote) ; $QNote = eregi_replace ( "\[color=gray\]", "<font color=999999> " , $QNote ) ; $QNote = eregi_replace ( "\[/color\]", " </font>" , $QNote ) ; $QNote = eregi_replace ( "\[glow\]"," <table style=filter:glow(color=pink, strength=3)> ", $QNote ) ; $QNote = eregi_replace ( "\[/glow\]", " </table>" , $QNote ) ; $QNote = eregi_replace ( "\[shadow\]","<table style=\"filter:shadow(color=pink, direction=left)\"> ", $QNote ) ; $QNote = eregi_replace ( "\[/shadow\]", " </table>" , $QNote ) ; // ให้ขึ้นบันทัดใหม่ กรณีที่มีการเคาะ Enter $QNote = eregi_replace(chr(13)," <br> ", $QNote ); $QNote = eregi_replace("(^|[>[:space:]\n])([[:alnum:]]+)://([^[:space:]]*)([[:alnum:]#?/&=])([<[:space:]\n]|$)","<a href=\"\\2://\\3\\4\" target=\"_blank\">\\2://\\3\\4</a>", $QNote ); $QNote = eregi_replace("([[:alnum:]]+)@([^[:space:]]*)([[:alnum:]])([<[:space:]\n]|$)","<a href=mailto:\\1@\\2\\3\>\\1@\\2\\3</a>", $QNote ); //ตรวจสอบการโพสกระทู้ (ห้ามโพสเกิน จำนวนที่ระบุใน config) CheckFlood($IP); // ตรวจสอบว่าเป็นสมาชิกหรือไม่ $sql = "select User,Password,Email from webboard_member where User='$QName'"; $result = mysql_db_query($dbname,$sql); $NRow = mysql_num_rows($result); $row = mysql_fetch_array($result); $Member = $row["User"]; // ตรวจสอบว่า Password ถูกหรือไม่ if($QName==$row["User"] && $QPass==$row["Password"]) { $Member = 1; if(!$QEmail) { $QEmail = $row["Email"]; } }else { $Member = 0; } if(strcmp($_POST['code_input'],$_POST['code_hidden'])==0){ // ทำการ เพิ่มค่าการโพสของสมาชิก if($Member) { $sql3 = "update webboard_member set m_post=m_post+1 where User='$QName'"; $result3 = mysql_db_query($dbname,$sql3); } else { }; // จบการทำงาน // บันทึกรูปภาพ if(($QNote =='')&&($QName=='')) { echo "<center >"; echo "<font size=+1 color=\"red\">"; echo "ข้อความส่งมาไม่สมบูรณ์อาจใส่ข้อมูลไม่ครบ หรือตกหล่นระหว่างการส่งข้อมูล กรุณาส่งข้อความอีกครั้ง<br><br>"; echo "<font size=+1 color=red >"; echo "<a href='javascript:history.back(1)'>[ กลับไปแก้ไข ] </a>"; echo "</font>"; echo "</center>"; exit(); } if( $QPic !='') { srand((double)microtime()*1000000); $QPic = $_FILES['QPic']['tmp_name']; $QPic_name = $_FILES['QPic']['name']; $QPic_size = $_FILES['QPic']['size']; $QPic_type = $_FILES['QPic']['type']; $QPic_name=$random_pic = rand(1,9999); # ตรวจสอบความกว้างของรูป if ( isset($_FILES['QPic']) && $_FILES['QPic']['error'] === UPLOAD_ERR_OK && $_FILES['QPic']['tmp_name'] != '' ) { $QPic = $_FILES['QPic']['tmp_name']; $QPic_name = $_FILES['QPic']['name']; $QPic_size = $_FILES['QPic']['size']; $QPic_type = $_FILES['QPic']['type']; // ตรวจสอบว่าเป็นไฟล์ภาพจริง $size = @getimagesize($QPic); if ($size === false) { echo "<center><font color=red>ไฟล์ที่อัปโหลดไม่ใช่รูปภาพ</font></center>"; exit(); } } # ตรวจสอบขนาดของ Flash if ( $QPic_type == "application/x-shockwave-flash" ) { if($QPic_size>$flashSize_limit) { echo "<br><b><center><font size=3 color=red >ขนาดของไฟล์ Flash เกิน $flashSize_limit bytes [$flashSize_msg]</font></center></b><br>"; echo "<br><b><center><font size=3 color=red >[ <a href='javascript:history.back(1)'>กลับไปแก้ไข</a> ]</font></center></b>"; exit(); } } else { # ตรวจสอบขนาดของรูป if($QPic_size>$Image_size) { echo "<br><b><center><font size=3 color=red >ขนาดของภาพเกิน $Image_size bytes [$Image_msg]</font></center></b><br>"; echo "<br><b><center><font size=3 color=red >[ <a href='javascript:history.back(1)'>กลับไปแก้ไข</a> ]</font></center></b>"; exit(); } } #แปลงนามสกุล และทำการ upload if ( $QPic_type == "image/gif" ) { $filename = $QPic_name.".gif"; } if ( $QPic_type == "image/bmp" ) { $filename = $QPic_name.".bmp"; } if ( $QPic_type == "image/png" ) { $filename = $QPic_name.".png"; } if ( $QPic_type == "application/x-shockwave-flash" ) { $filename = $QPic_name.".swf"; } elseif (($QPic_type=="image/jpg")||($QPic_type=="image/jpeg")||($QPic_type=="image/pjpeg")) { $filename =strtolower($QPic_name.$random_pic . '.jpg'); } move_uploaded_file($QPic, "$path/" . $filename); } elseif ($QPic == "") { echo ""; } // เวลาจะตรงกับเครื่อง server ที่เรารัน $mdate = date("Y-m-d H:i:s"); // ตรวจสอบว่าเป็นสมาชิกหรือไม่ ที่สามารถโพสประกาศได้ $sql2 = "select User from webboard_member where User='$QName' and Password='$QPass' and status='1' "; $result2 = mysql_db_query($dbname,$sql2); $row2 = mysql_fetch_array($result2); $Member2 = $row2["User"]; // เช็ค username ว่าให้สามารถโพสข่าวประกาศได้ไหม if($Member2 && $pst==1) { $mp = 1; } else { $mp = 0; } //สคริปดักกระทู้ขยะก่อนลงฐานข้อมูล /* if(ereg("www",$_POST[QNote]) || ereg("http",$_POST[QNote]) || ereg("<a href",$_POST[QNote]) || ereg("<",$_POST[QNote])){ echo "\n"; echo "<center>"; echo "<BR><BR><a href='javascript:history.back(1)' class='styles2'> กรุณกรอกข้อมูลให้ถูกต้อง</a><BR><BR><BR><BR>"; exit; }*/ // เขียนข้อมูลลง database $sql = "insert into webboard_data (Category,Question,Note,Name,Namer,Member,IP,Email,Date,nphoto,resolution,pst) values ('$Category','$QTitle','$QNote','$QName','$MsgBy','$Member','$IP','$QEmail','$mdate','$filename','$size[0]','$mp')"; $result1 = mysql_db_query($dbname,$sql); mysql_close(); ?> </div></td> </tr> <tr> <td><div align="center"> <table width=60% border=0 bgcolor=#000000 cellpadding=7 cellspacing=1> <tr> <td align=center bgcolor=#ffffff class="styles3"><span class="red">ได้รับข้อมูลแล้วครับ</span><br> <br> หากกลับไปหน้าแรกแล้วคำถามของคุณยังไม่ขึ้นให้ลองกดปุ่ม Refresh/Reload ครับ </font></td> </tr> </table> </div></td> </tr> <tr> <td> </td> </tr> <tr> <td class="styles3"><div align="center">| <a href="webboard.php?Category=<? echo $Category; ?>" class="styles2">แสดงคำถาม</a> || <a href="postq.php?Category=<? echo $Category; ?>" class="styles2">ตั้งกระทู้ใหม่ </a>|</div></td> </tr> <? } else{ echo "<br><b><center><span class=red>กรุณาใส่ค่า Verification code</span></center></b><br>"; echo "<br><b><center><span class=styles1 >[ <a href='javascript:history.back(1)' class=styles2>กลับไปแก้ไข</a> ]</span></center></b>"; } ?> <tr> <td> </td> </tr> </table> <!-- InstanceEndEditable --></td> </tr> </table></td> </tr> <tr> <td align="center" valign="top"> </td> </tr> <tr> <td align="center" valign="top"> </td> </tr> <tr> <td align="center" valign="top" style="background-repeat:no-repeat"><img src="../images/foot.png"></td> </tr> </table> </div> <!-- end_content --> <tr><td><a style="display:scroll;position:fixed;bottom:5px;right:5px;" class="backtotop" href="#top" rel="nofollow" title="Back to Top"><img src="../images/up.png" border="0" /></a></td> </tr> <map name="Map6" id="Map6"><area shape="rect" coords="210,1,302,41" href="http://www.tratlocal.go.th/index.php" target="_blank" /> </map> </body> <!-- InstanceEnd --></html>
©
2018.