-
Notifications
You must be signed in to change notification settings - Fork 1
/
comment.php
59 lines (37 loc) · 846 Bytes
/
comment.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
<?php session_start();?>
<?php
$reviewid = $_POST["flag1"];
$rs = "";
$commenttext = $_POST["flag2"];
include "db.php";
function checkintruder($query)
{
if (preg_match('/[\'}{@#~?><>/', $query))
{
return false;
}
else
{
return true;
}
}
$timestamp = time();
$username = $_SESSION['username'];
$commentid = $reviewid . "_comments_" . $timestamp;
$count =0;
$query = "select reviewid from reviewdb where ( reviewid = '$reviewid') ";
$results = mysqli_query($con, $query);
while($row = mysqli_fetch_array($results))
{
$count++;
}
if(checkintruder($commenttext) && $commenttext != "")
{
$query = "insert into commentdb values ('$commentid', '$reviewid', '$username', '$commenttext', '$timestamp') ";
$results = mysqli_query($con, $query);
}
/*
header('content-type: application/json');
echo json_encode($rs);
*/
?>