<?php
// QuickTicket 2.5 build:20101222
include('bin/qt_lib_txt.php');
include('bin/qt_lib_db.php');
include('bin/qti_fn_base.php');
include('bin/qti_fn_html.php');
// Protection against injection (accept only 4 'lang')
$id = strip_tags($_POST['id']);
$lang = strip_tags($_POST['lang']);
if ( !in_array($lang,array('language/english/','language/francais/','language/nederlands/','language/espanol/')) ) $lang='language/english/';
$dir = strip_tags($_POST['dir']);
$id = intval(substr($id,1));
include($lang.'qti_main.php');
include('bin/config.php');
$oDBAJAX = new cDB($qti_dbsystem,$qti_host,$qti_database,$qti_user,$qti_pwd,$qti_port,$qti_dsn);
if ( !empty($oDBAJAX->error) ) exit;
// query
$oDBAJAX->Query('SELECT * FROM '.$qti_prefix.'qtiuser WHERE id='.$id);
$row = $oDBAJAX->GetRow();
//output the response
echo AsImgBox(
(empty($row['photo']) ? '' : AsImg($dir.$row['photo'],'',$row['name'],'member')),
'picbox',
'',
$row['name'].'<br />('.QTconv($L['Userrole'][$row['role']],'5').')'.(empty($row['location']) ? '' : '<br />'.QTconv($row['location'],'5'))
);
?>