require "login.php";
include("header.inc.php");
include("config.php");
mysql_connect( "$dbhost", "$dbuser", "$dbpass") or die("$wort_konnte_datenbankverbindung_nicht_herstellen");
@mysql_select_db( "$dbname") or die("$wort_datenbank_nicht_gefunden");
if($action=="ja") {
if ($_POST['nick'] !="" && $_POST['kommentar'] !="") {
$zeit=time();
$host=$_SERVER['REMOTE_ADDR'];
// HTML check
$kommentar= htmlspecialchars($_POST['kommentar']);
$kommentar= nl2br($kommentar);
mysql_query("insert into $tablekom values ('','$_POST[fileid]','$_POST[nick]','$kommentar','$zeit','$host')");
echo "
| $wort_vielen_dank_fuer_deinen_kommentar $_POST[nick] |
";
} else {
echo "| $wort_bitte_die_felder_ausfuellen! |
";
}
} else {
echo"
| $wort_kommentare: |
";
$odd_even="odd";
$result = mysql_query("select * from $tablekom where fileid='$_GET[fileid]' order by zeit desc");
while($row=mysql_fetch_array($result)) {
$komid=$row["id"];
$nick=$row["nick"];
$kommentar=$row["kommentar"];
$zeit=$row["zeit"];
if ($odd_even=="even") {$odd_even="odd";
} else {$odd_even="even";}
$zeit_anzeige=date("d.m.Y, H:i",$zeit);
echo "
$nick $zeit_anzeige
 |
$kommentar |
";
}
?>
echo "
";
}
include("footer.inc.php");
?>