OverLord Shell

Path : G:/PleskVhosts/jaincensus.com/macciaweb.ultraliant.com/businessforum/
File Upload :
Current File : G:/PleskVhosts/jaincensus.com/macciaweb.ultraliant.com/businessforum/productreviewadd_save.php

<?php
/*
@Purpose: add company location into database
@Author: Rajashree
@CreatedOn: 5 May 2016
@ModifiedOn: 5 May 2016
*/
error_reporting(0);
session_start();

if(!isset($_SESSION['company_id']) || !isset($_SESSION['company_name'])){session_destroy();echo "login.php";exit;}
if(!in_array($_SESSION['loggedin_user'],array('admin','company'))){echo "404.php";exit;}
if($_SERVER['REQUEST_METHOD']!='POST' || empty($_POST)){echo "404.php";exit;}
require_once("db/conn.php");

$prod=explode("~", $_POST['product_id']);
$my_comp=explode("~", $_POST['my_company_id']);

$company_name=$_POST['company_name'];


    $review = htmlentities($_POST['review'],ENT_QUOTES);
    $patterns = array();
    $patterns[0] = '/([a-zA-Z0-9_\-\.]+)@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.)|(([a-zA-Z0-9\-]+\.)+))([a-zA-Z]{2,4}|[0-9]{1,3})(\]?)/';
    $patterns[1] = '/([0-9]+[\- ]?[0-9]{9}+)/';
	$patterns[2] = '/([0-9]{2,}-[0-9]{0,}-[0-9]{0,})/';
	$patterns[3] =  "/(http|https|ftp|ftps)\:\/\/[a-zA-Z0-9\-\.]+\.[a-zA-Z]{2,3}(\/\S*)?/";
	
    $replacements = array();
    $replacements[0] = '';
    $replacements[1] = '';
	$replacements[2] = '';
	$replacements[3] = '';

    //should use just one call of preg_replace for perfomance issues
    $string = preg_replace($patterns, $replacements, $review);
$data = array(

		'name' => $_POST['name'],
		'product_id' => $prod[0],
		'product_name' => $prod[1],
		'company_id' => $_SESSION['company_id'],
		'my_company_id' => $my_comp[0],
		'my_company_name' => $my_comp[1],
		'email' =>$_POST['email'],
		'mobile' => $_POST['mobile'],
		'review' => $string,
		'createdby' => $_SESSION['company_id'],
		'createdon' => date('Y-m-d H:i:s'),
		'review_date' => date('Y-m-d H:i:s')
		
	);
	//print_r($data);exit;
	$insertresult = dbRowInsert('busdir_mst_product_review', $data);
	$insertresultarr = explode("-",$insertresult);
	
	echo $insertresultarr[0];
?>

xRyukZ - Copyright 2k19