PHP-Code:
<?
include('../access.php');
include('../forum/mysql.php');
$unter = $HTTP_POST_VARS["unter"];
$del = $HTTP_POST_VARS["del"];
$pass = $HTTP_POST_VARS["pass"];
$titel = $HTTP_POST_VARS["titel"];
$send = $HTTP_POST_VARS["send"];
$inhalt = "$send";
// Sichergehen, dass die Datei existiert und beschreibbar ist
$trans = get_html_translation_table(HTML_ENTITIES);
$str = "$inhalt";
$encoded = strtr($str, $trans);
//BILD
$encoded = str_replace("[IMG]","<img src=' ",$encoded);
$encoded = str_replace("[/IMG]"," '>",$encoded);
//InlineFrame
$encoded = str_replace("[IFRAME]","<iframe src='",$encoded);
$encoded = str_replace("[IFRAME2]","' height='",$encoded);
$encoded = str_replace("[IFREAME3]","' width='",$encoded);
$encoded = str_replace("[IFRAME4]","'>",$encoded);
//BILD mit grösse
$encoded = str_replace("[IMGG]","<img src=' ",$encoded);
$encoded = str_replace("[IMGG2]","' width='",$encoded);
$encoded = str_replace("[IMGG3]","' height='",$encoded);
$encoded = str_replace("[IMGG4]","'>",$encoded);
//Bild mit hover Inhalt
$encoded = str_replace("[ALT]","' alt='",$encoded);
$encoded = str_replace("[/IMG]","'>",$encoded);
//enter
$encoded = str_replace("[SPACE]","
",$encoded);
//Kursiv
$encoded = str_replace("[K]","[i]",$encoded);
$encoded = str_replace("[/K]","[/i]",$encoded);
//Fett
$encoded = str_replace("[F]","[b]",$encoded);
$encoded = str_replace("[/F]","[/b]",$encoded);
//Farbcode
$encoded = str_replace("[PAINT]","<font color='",$encoded);
$encoded = str_replace("[PAINT1]","'>",$encoded);
$encoded = str_replace("[PAINT2]","</font>",$encoded);
//Textgrösse
$encoded = str_replace("[SIZE]","<font size='",$encoded);
$encoded = str_replace("[SIZE1]","'>",$encoded);
$encoded = str_replace("[SIZE2]","</font>",$encoded);
//url
$encoded = str_replace("[url]","<a href='",$encoded);
$encoded = str_replace("[URL1]","'>",$encoded);
$encoded = str_replace("[URL2]","</a>",$encoded);
//center
$encoded = str_replace("[center]","<center>",$encoded);
$encoded = str_replace("[/center]","</center>",$encoded);
//left
$encoded = str_replace("[left]","<p align='left'>",$encoded);
$encoded = str_replace("[/left]","</p>",$encoded);
//right
$encoded = str_replace("[right]","<p align='right'>",$encoded);
$encoded = str_replace("[/right]","</p>",$encoded);
//Lauftext
$encoded = str_replace("[LAUFTEXT]","<marquee>",$encoded);
$encoded = str_replace("[/LAUFTEXT]","</marquee>",$encoded);
//sonder
$encoded = str_replace("Entetrente","Entetrente [Webmaster]",$encoded);
//smileys
$encoded = str_replace(":o",'[img]images/smile/4a5b523f61243ac34bcf6c7b6968fb78.gif[/img]',$encoded);
$encoded = str_replace(":)","<img sec='images/smile/5c3fef07afbe3bf1a788db4240c310b7.gif'>",$encoded);
$encoded = str_replace(":D","<img sec='images/smile/5e75600286b954700e18b45234807070.gif'>",$encoded);
$encoded = str_replace(":(","[img]images/smile/6e151f624b9f3003b84f1a45bd76397f.gif[/img]",$encoded);
$encoded = str_replace("^:(","[img]images/smile/9ae16c4dd6cbb0b7cbae9d5ee51f53c0.gif[/img]",$encoded);
$encoded = str_replace("^^:!","[img]images/smile/9bfed21332501cedcfcb78c731f694b7.gif[/img]",$encoded);
$encoded = str_replace("?:)","[img]images/smile/9e6ae28da5163501e52f7439b058ad8f.gif[/img]",$encoded);
$encoded = str_replace("oo)","[img]images/smile/77cb307df6ee5a5b82d7b59e6dc42078.gif[/img]",$encoded);
$encoded = str_replace(":((","[img]images/smile/0559cffa6b1f50bb62b640c147975490.gif[/img]",$encoded);
$encoded = str_replace("^^)","[img]images/smile/973dbe66f7fe77cba44ff04b6d53f02c.gif[/img]",$encoded);
$encoded = str_replace("X)","[img]images/smile/3339c31399534aa015f7ab14b182ba99.gif[/img]",$encoded);
$encoded = str_replace("H)","[img]images/smile/7056c9af805590d370b6942d56e40ded.gif[/img]",$encoded);
$encoded = str_replace("^^(","[img]images/smile/241821cd256d593e0859e81f4bfbe81a.gif[/img]",$encoded);
$encoded = str_replace(";)","[img]images/smile/a6f48ea4d47ead5440a484b1679716d5.gif[/img]",$encoded);
$encoded = str_replace(":o)","[img]images/smile/c5acb32a3575a93e20f5b7dfaba4b460.gif[/img]",$encoded);
$encoded = str_replace(":P","[img]images/smile/dc8643659faa48bbde965d5dc208b86c.gif[/img]",$encoded);
$encoded = str_replace(":lD","[img]images/smile/ed40cdaa88e6f2d38ddacdcd33527867.gif[/img]",$encoded);
$encoded = str_replace(";DD","[img]images/smile/f9d9e45dfbb72a2b564f27921f7c1276.gif[/img]",$encoded);
$encoded = str_replace(":X","[img]images/smile/f008874df7d3848c8f19b91d9bc52dbf.gif[/img]",$encoded);
mysql_real_escape_string($encoded);
$eintrag = "INSERT INTO page (titel, beschreibung, inhalt, von, datum) VALUES ('$titel', '$betreff',
'$encoded', '$nom',NOW())";
$eintragen = mysql_query($eintrag) or die($eintrag . ":
\n" . mysql_error());
print "message wurde verschickt";
?>