// // Alternatively, the contents of this file may be used under the terms of // either the GNU General Public License Version 2 or later (the "GPL"), or // the GNU Lesser General Public License Version 2.1 or later (the "LGPL"), // in which case the provisions of the GPL or the LGPL are applicable instead // of those above. If you wish to allow use of your version of this file only // under the terms of either the GPL or the LGPL, and not to allow others to // use your version of this file under the terms of the MPL, indicate your // decision by deleting the provisions above and replace them with the notice // and other provisions required by the GPL or the LGPL. If you do not delete // the provisions above, a recipient may use your version of this file under // the terms of any one of the MPL, the GPL or the LGPL. // // ***** END LICENSE BLOCK ***** //Inappropriate Comment Reporting Tool require"../core/config.php"; //Check and see if the CommentID/ID is valid. $sql = "SELECT `ID`, `CommentID` FROM `feedback` WHERE `ID` = '".escape_string($_GET[id])."' AND `CommentID`='".escape_string($_GET["commentid"])."' LIMIT 1"; $sql_result = mysql_query($sql, $connection) or trigger_error("MySQL Error ".mysql_errno().": ".mysql_error()."", E_USER_ERROR); if(mysql_num_rows($sql_result)=="0") { unset($_GET["id"],$_GET["commentid"],$id,$commentid); } else { $id = escape_string($_GET["id"]); $commentid = escape_string($_GET["commentid"]); } //Make Sure action is as expected. if ($_GET["action"]=="report") { $action="yes"; } if (!$commentid or !$action ) { //No CommentID / Invalid Action --> Error. page_error("4","No Comment ID or Action is Invalid"); exit; } //Set Flag on the Comment Record $sql = "UPDATE `feedback` SET `flag`='YES' WHERE `CommentID`='$commentid' LIMIT 1"; $sql_result = mysql_query($sql, $connection) or trigger_error("MySQL Error ".mysql_errno().": ".mysql_error()."", E_USER_NOTICE); if ($_GET["type"]=="E") { $type="extensions"; } else if ($_GET["type"]=="T") { $type="themes"; } $return_path="$type/moreinfo.php?id=$id&vid=$vid&".uriparams()."&page=comments&pageid=$_GET[pageid]#$commentid"; ?>