include("includes/session.maintainence.php");
include("includes/config.php");
include("includes/connect.php");
include("includes/common.functions.php");
include("includes/Pager.Class.php");
include("includes/lib.mail.php");
$cmd = $_REQUEST['cmd'];
if(!isset($cmd))$cmd=1;
if(empty($cmd))$cmd=1;
switch($cmd)
{
case 1:
$title = "Welcome To ".$siteName;
$my_file = "message.center.php";
$error="";
//$name = trim($_REQUEST['name']);
$email = trim($_REQUEST['email']);
$txtpassword = trim($_REQUEST['txtpassword']);
//$logintype=trim($_REQUEST['logintype']);
if(isset($_POST["submitLogin"])){
/*if($email==""){
$error.="Please enter email !
";
}else{
if(!ValidEmail($email)){
$error.="Please enter Valid email !
";
}
}
if($txtpassword==""){
$error.="Please enter password !";
}
if(($email!="")&&($txtpassword!="")&&($error=="")){ //ss
if(ValidEmail($email)){ //validemail
$sql="select * from hum_med_user where login_name='".$email."'";
$result=mysql_query($sql);
$count=mysql_num_rows($result);
if($count >0){
$error.="This Id alraedy in use !";
}else{
mysql_query("insert into hum_med_user(login_name,user_name,password,status) values('".$email."','".$name."','".$txtpassword."','1')");
session_register("user_login");
$_SESSION['user_login']=$email;
$email="";
$name="";
$myurl="Location:".$siteurl."index.php?cmd=2";//"user.home.php?";
redirectMe($myurl);
}
}//validemail
} //ss
}else{ //firstlogin
if($name==""){
$error="Please enter name !
";
}*/
if($email==""){
$error.="Please enter email !
";
}else{
if(!ValidEmail($email)){
$error.="Please enter Valid email !
";
}
}
if($txtpassword==""){
$error.="Please enter password !";
}
if(($email!="")&&($txtpassword!="")&&($error=="")){
if(ValidEmail($email)){
$sql="select * from hum_med_user where login_name='".$email."' and password='".$txtpassword."' and status='1'";
$result=mysql_query($sql);
$count=mysql_num_rows($result);
if($count >0){
session_register("user_login");
$_SESSION['user_login']=$email;
$email="";
$name="";
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
}else{
$error="Incorrect Login !";
}
}
}
//}//else
}
break;
case 2:
$title = "Welcome To ".$siteName;
$my_file="user.home.php";
break;
case 3:
$title = "Welcome To ".$siteName;
$my_file="new.message.thread.php";
$merror="";
if(isset($_POST["submitLogin"])){
$title=$_REQUEST['txttitle'];
//$txtmessage=$_REQUEST['txtmessage'];
$txtmessage=$_REQUEST['myHid'];
$oldcontent=$_REQUEST['myHid'];
if($title==""){
$merror="Please enter Title !
";
}
if($txtmessage==""){
$merror.="Please enter Message ! ";
}
if($merror==""){
$userid=GetField("user_id","hum_med_user","login_name='".$_SESSION['user_login']."'");
$sql="insert into hum_med_message(user_id,creation_date,mess_title,message,reply_id,status) values('".$userid."',now(),'".$title."','".$txtmessage."' , '0','1')";
mysql_query($sql);
$txtmessage="";
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
}
}
break;
case 4:
$title = "Welcome To ".$siteName;
$user_id=$_GET['uid'];
$my_file="log.all.message.threads.php";
break;
case 5:
$title = "Welcome To ".$siteName;
$my_file="forgot.password.php";
$lerror="";
if(isset($_POST['forgotLogin'])){
$email=$_REQUEST['txtemail'];
if($email==""){
$lerror="Please enter Email id !";
}else{
if(!ValidEmail($email)){
$lerror="Please enter valid Email id !";
}
}
if($lerror==""){
if(ValidEmail($email)){
$sql="select * from hum_med_user where login_name='".$email."'";
$result=mysql_query($sql);
$count=mysql_num_rows($result);
if($count > 0){
$obj=mysql_fetch_object($result);
$name=$obj->user_name;
$login_name=$obj->login_name;
$password=$obj->password;
$message="User Name :".$name."
Login Name: ".$login_name."
Password : ".$password;
$headers = "MIME-Version: 1.0\r\n";
$headers .= "Content-type: text/html; charset=iso-8859-1\r\n";
mail($email,"Forgot Password",$message,$headers);
//$myurl="Location:".$siteurl."index.php?cmd=1";
//redirectMe($myurl);
$conmessage="Your User Name And Password has been sent to your E-Mail Address !" ;
}else{
$lerror="This id is not pressent !";
}
}
}
}
break;
case 6:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$my_file="details.message.php";
break;
case 7:
$title = "Welcome To ".$siteName;
$user_id=$_GET['uid'];
$my_file="all.message.threads.php";
break;
case 8:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$my_file="message.repply.php";
$error="";
if(isset($_POST['submitRepply'])){
$title=$_REQUEST['txttitle'];
//$message=$_REQUEST['txtmessage'];
$message=$_POST['myHid'];
$oldcontent=$_POST['myHid'];
$repplymail=$_REQUEST['txtrepply'];
if($title==""){
$error="Please enter Title !
";
}
if($message==""){
$error.="Please enter Message !";
}
if($error==""){
if($repplymail==""){
$userid=GetField("user_id","hum_med_user","login_name='".$_SESSION['user_login']."'");
$repply=GetField("reply_status","hum_med_message","mess_id='".$mid."'");
if($repply=='1'){
$sql="insert into hum_med_message(user_id,creation_date,mess_title,message,reply_id,status,reply_status) values('".$userid."',now(),'".$title."','".$message."' ,'".$mid."','1','1')";
mysql_query($sql);
$message="";
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
}else{
$error="You can't repply Date of message has been expaired !";
}
}else{
if($repplymail!=""){
$userid=GetField("user_id","hum_med_user","login_name='".$_SESSION['user_login']."'");
$sql="insert into hum_med_message(user_id,creation_date,mess_title,message) values('".$userid."',now(),'".$title."','".$message."')";
mysql_query($sql);
$headers = "MIME-Version: 1.0\r\n";
$headers .= "Content-type: text/html; charset=iso-8859-1\r\n";
mail($repplymail,$title,$message,$headers);
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
}
}
}
}
break;
case 9:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$my_file="edit.message.thread.php";
if(isset($_POST["editMessage"])){
$emerror="";
$title=$_REQUEST['txttitle'];
//$txtmessage=$_REQUEST['txtmessage'];
$txtmessage=$_POST['myHid'];
$oldcontent=$_POST['myHid'];
if($title==""){
$emerror="please enter title !
";
}
if($txtmessage==""){
$emerror.="Please enter message !";
}
if($emerror==""){
$sql="update hum_med_message set creation_date=now(),mess_title='".$title."', message='".$txtmessage."' where mess_id='".$mid."'";
mysql_query($sql);
$txtmessage="";
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
}
}else{
$query="select * from hum_med_message where mess_id='".$mid."'";
$rs=mysql_query($query);
$obj=mysql_fetch_object($rs);
$name=GetField("user_name","hum_med_user","user_id='".$obj->user_id."'");
$email=GetField("login_name","hum_med_user","user_id='".$obj->user_id."'");
$oldcontent=$obj->message;
}
break;
case 10:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$sql="delete from hum_med_message where mess_id='".$mid."'";
mysql_query($sql);
$myurl="Location:".$siteurl."index.php?cmd=2";
redirectMe($myurl);
break;
case 11:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$my_file="all.repply.message.center.php";
break;
case 12:
$title = "Welcome To ".$siteName;
$mid=$_GET['mid'];
$my_file="all.repply.message.threads.php";
break;
case 13:
$title = "Welcome To ".$siteName;
$my_file = "newlogin.php";
$error="";
$name = trim($_REQUEST['name']);
$email = trim($_REQUEST['email']);
$txtpassword = trim($_REQUEST['txtpassword']);
$schoolaff=trim($_REQUEST['schoolaff']);
if(isset($_POST["submitLogin"])){
if($name==""){
$error="Please enter name !
";
}
if($email==""){
$error.="Please enter email !
";
}else{
if(!ValidEmail($email)){
$error.="Please enter Valid email !
";
}
}
if($txtpassword==""){
$error.="Please enter password !
";
}
if($schoolaff==""){
$error.="Please enter School Affiliation !";
}
if(($email!="")&&($txtpassword!="")&&($error=="")){ //ss
if(ValidEmail($email)){ //validemail
$sql="select * from hum_med_user where login_name='".$email."'";
$result=mysql_query($sql);
$count=mysql_num_rows($result);
if($count >0){
$error.="This Id alraedy in use !";
}else{
mysql_query("insert into hum_med_user(login_name,user_name,password,status,scoolaffiliation) values('".$email."','".$name."','".$txtpassword."','1','".$schoolaff."')");
session_register("user_login");
$_SESSION['user_login']=$email;
$email="";
$name="";
$myurl="Location:".$siteurl."index.php?cmd=2";//"user.home.php?";
redirectMe($myurl);
}
}//validemail
}
}
break;
case 14:
$title = "Welcome To ".$siteName;
$my_file="instructions.php";
break;
case 15:
$title = "Welcome To ".$siteName;
$my_file="aboutus.php";
break;
case 16:
$title = "Welcome To ".$siteName;
$my_file="contactus.php";
$comerror="";
//$comerror="Please Enter Your E-mail !";
if(isset($_POST['Submitcomment'])){
$mesemail=$_REQUEST['mesemail'];
$message=$_REQUEST['mescomments'];
if($mesemail==""){
$comerror="Please Enter Your E-mail !
";
}else{
if(!ValidEmail($mesemail)){
$comerror.="Please enter Valid email !
";
}
}
if($message==""){
$comerror.="Please enter Message !
";
}
if($comerror==""){
$m= new Mail;
$m->From( $mesemail);
$m->Subject("Ethics Challenge" );
$m->Body($message);
$m->Priority(4) ;
$m->To( "goldfdtn@gold-foundation.org" );
$m->Send();
unset($m);
$message="";
$mesemail="";
$comerror=" Thanks!
Your Comments has been sent successfully.";
//$myurl="Location:".$siteurl."index.php?cmd=1";//"user.home.php?";
//redirectMe($myurl);
}
}
break;
}
include("includes/header.php");
echo "
| "; include($my_file); echo " |