/*
Template Name: Email Us
*/
get_header();
require("pf-keyvars.php");
require("pf-functions.php");
require("pf-dbconn.php");
if ($_POST["SUBMIT"] == "Submit" && $pfhost == parse_url($_SERVER["HTTP_REFERER"], PHP_URL_HOST)) {
$goodsubmission=true;
foreach(array_keys($_POST) as $key)
$clean[$key] = mysql_real_escape_string($_POST[$key]);
foreach(array_keys($clean) as $key) {
if (substr($key,0,6) == "FIELD_") {
// minimize spamming by rejecting web address submissions:
// echo "
".$key.": ".$clean[$key]. " - result: ".strpos(strtolower($clean[$key]),"http");
// if(!(strpos(strtolower($clean[$key]),"http") == false))
// $goodsubmission=false;
$sqlstr1.=substr($key,6,strlen($key)-6).",";
$sqlstr2.="'".$clean[$key]."',";
}
}
if($goodsubmission && !IsSpam(strtolower(mysql_real_escape_string($_POST['FIELD_CLIENTSERVICEREQUEST'])))) {
// prepareware submission:
$conn = mssql_connect($tds_server, $tds_dbuser,$tds_dbpw);
mssql_select_db($tds_dbname);
$sqlstr="insert into preparewarecustomer..CustomerService (".substr($sqlstr1,0,strlen($sqlstr1)-1).") values (".substr($sqlstr2,0,strlen($sqlstr2)-1).")";
$query = mssql_query($sqlstr);
if (!$query)
$errortext="
Database error during insert to PrepareWare: ".mssql_get_last_message;
// MySQL submission
$sqlstr="insert into CustomerService (".substr($sqlstr1,0,strlen($sqlstr1)-1).",EntryDate) values (".substr($sqlstr2,0,strlen($sqlstr2)-1).",now())";
if (!mysql_query($sqlstr))
die("a database error occurrred");
// handle any uploaded files
$emailstr_files = f_ProcessFiles("www");
$emailbody = "
".$sentdate." | |
---|---|
".str_replace("_"," ",$key)." | ".nl2br($value)." |