<?php
require_once("functions.php");
DBOpen();
LoginOpt();
MyHeader();
if(!isset($_POST[login])) {
echo "<FORM METHOD=POST STYLE='display:inline;'>";
echo "<TABLE CELLSPACING=3 CELLPADDING=3>";
echo "<TR>";
echo "<TD>Domain</TD><TD><INPUT TYPE=TEXT NAME=domain></TD>";
echo "</TR><TR>";
echo "<TD>Password</TD><TD><INPUT TYPE=PASSWORD NAME=password> <INPUT TYPE=SUBMIT NAME=login VALUE='Login'></TD>";
echo "</TR>";
echo "</TABLE>";
echo "</FORM>";
} else {
$u_domain = strip_tags(trim($_POST[domain]));
$u_password = strip_tags(trim($_POST[password]));
$res = DBQuery("SELECT count(user_id) as u_exist, max(user_id) as u_id, max(user_domain) as u_dom FROM users WHERE user_name = '$_REQUEST[conf_adminuser]@$u_domain' AND user_password = encrypt('$u_password',user_password)");
$row = mysql_fetch_assoc($res);
if($row[u_exist]==0) {
if(($_REQUEST[adm_name]==$u_domain)&&($_REQUEST[adm_password]==md5($u_password))) {
$row[u_exist]=1;
$row[u_id]=$_REQUEST[adm_id];
$row[u_dom]=0;
}
}
if($row[u_exist]==1) {
$tmp = md5($row[u_id] . date);
DBQuery("INSERT INTO sessions (ses_user,ses_key,ses_ip,ses_dom_id,ses_expiredate) VALUES ($row[u_id],'$tmp','$_SERVER[REMOTE_ADDR]',$row[u_dom],FROM_UNIXTIME(".(time()+3600)."))");
setcookie($_REQUEST[conf_Cookie], $tmp, time()+3600);
header("Location: index.php");
} else {
header("Location: logout.php");
}
}
DBClose();
MyFooter();
MyEnd();
?>