Пример #1
0
Файл: api.php Проект: I0T/xss
        $domain = StripStr($domain);
        $serverContent['HTTP_REFERER'] = StripStr($_SERVER['HTTP_REFERER']);
        $serverContent['HTTP_USER_AGENT'] = StripStr($_SERVER['HTTP_USER_AGENT']);
        $user_ip = $_SERVER['HTTP_X_FORWARDED_FOR'];
        if ($user_ip == '') {
            $user_ip = $_SERVER['REMOTE_ADDR'];
        }
        $serverContent['REMOTE_ADDR'] = StripStr($user_ip);
        $values = array('projectId' => $project['id'], 'content' => JsonEncode($content), 'serverContent' => JsonEncode($serverContent), 'domain' => $domain, 'cookieHash' => $cookieHash, 'num' => 1, 'addTime' => time());
        //$db->AutoExecute(Tb('project_content'),$values);
        $judgeCookie = in_array('cookie', $keys) ? true : false;
        /* cookie hash */
        $Getcookie = $content['cookie'];
        $db->AutoExecute(Tb('project_content'), $values);
        //Getcookie在上面的变量里
        $uid = $project['userId'];
        $userInfo = $db->FirstRow("SELECT * FROM " . Tb('user') . " WHERE id={$uid}");
        $msg = explode("|", $userInfo['message']);
        if ($userInfo['phone'] && $msg[1] == 1) {
            SendSMS('13800138000', '123456', $userInfo['phone'], "尊敬的" . $userInfo['userName'] . ",您在" . URL_ROOT . " 预订的猫饼干,Cookie:{$Getcookie}已经到货!详情请登陆:" . URL_ROOT . " 查看!");
            //参数:发送的飞信号 飞信密码
        }
        if ($userInfo['email'] && $msg[0] == 1) {
            SendMail($userInfo['email'], URL_ROOT . "饼干商城", "尊敬的" . $userInfo['userName'] . ",您在" . URL_ROOT . " 预订的猫饼干<br>Cookie:{$Getcookie}<br>已经到货!<br>详情请登陆:" . URL_ROOT . " 查看。");
            //Getcookie在上面的变量里
        }
    } else {
        $db->Execute("UPDATE " . Tb('project_content') . " SET num=num+1,updateTime='" . time() . "' WHERE projectId='{$project[id]}' AND cookieHash='{$cookieHash}'");
    }
    header("Location: {$_SERVER['HTTP_REFERER']} ");
}
Пример #2
0
    $result1 = mysql_fetch_row(mysql_query($query1));
    //obtain Book Info
    $query2 = "SELECT title FROM product2 WHERE productid='" . $prodid . "'";
    $result2 = mysql_fetch_row(mysql_query($query2));
    $samMsg = "An enquiry has been initiated for '{$result2['0']}' by {$data}";
    $url = "http://api.mVaayoo.com/mvaayooapi/MessageCompose?user="******":" . $pwd . "&senderID=" . urlencode("TEST SMS") . "&receipientno=" . $result1[0] . "&dcs=0&msgtxt=" . urlencode($samMsg) . "&state=4";
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $url);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    $final = curl_exec($ch);
    echo $final;
    curl_close($ch);
}
if (date("H", time() + 3600 * 5.5) < 21 && date("H", time() + 3600 * 5.5) > 9) {
    if (isset($_POST['msg'])) {
        SendSMS($_REQUEST['prodid'], $_REQUEST['userid'], $_POST['msg']);
    } else {
        ?>
<h3></h3>
<form action="<?php 
        echo $_SERVER['REQUEST_URI'];
        ?>
" method="POST">
	<input name="msg">
	<input type="submit" value="Send Enquiry">
</form>
<?php 
    }
} else {
    echo "Sorry, Book Requests can be sent only during 9 AM to 9 PM.<br> Please send request during this time period only.<br><br>Thank you";
}
        request_data($register_data);
        header('location:message.php');
        exit;
    }
}
if (isset($_post['submit']) === true) {
    if (isset($_post['notification']) === true && empty($_post['notification']) === false) {
        $branch = $user_data['branch'];
        $no = array();
        $query = "SELECT COUNT('user_id') FROM `members` WHERE `branch`='{$branch}'";
        $data = mysql_query($query);
        while ($row = mysql_fetch_assoc($data)) {
            $no[] = $row['mobile'];
        }
        $phone = implode(',', $no);
        $x = SendSMS("127.0.0.1", 8800, "akash", "prerna123", $phone, $_REQUEST['notification']);
        echo $x;
    } else {
        echo "ERROR : Message not sent -- Text parameter is missing!\r\n";
    }
} else {
    echo "ERROR : Message not sent -- Phone parameter is missing!\r\n";
}
?>
<td><div align="left" style="padding:20px"><h1>Messages</h1>   </div>

<?php 
$query = "SELECT * FROM `notifications` WHERE `type`='message'";
$data = mysql_query($query);
while ($row = mysql_fetch_assoc($data)) {
    echo '<div align="left" style="padding:20px">' . $row['notification'] . '<br>';