<?php
error_reporting (0);
include('sms_conf.php');
$dbc = mysql_connect($host,$user,$pass) or die("DB conection error");
mysql_select_db($db,$dbc);
$name=mysql_real_escape_string($_GET['name']);
$codigo=mysql_real_escape_string($_POST['codigo']);
$puntos=mysql_real_escape_string($_GET['puntos']);
if (isset($_POST['formcodigo']))
{
$name=mysql_real_escape_string($_POST['name']);
$QueryString = "LinkUrl=".urlencode((($_SERVER['HTTPS']=='on')?'https://':'http://').$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']);
$QueryString .= "&codigo=" .urlencode($codigo);
$QueryString .= "&idservicio=" .$idservicio;
$ch = curl_init ("http://contenidopago.com/codigoval.php?".$QueryString);
curl_setopt($ch, CURLOPT_TIMEOUT, 100);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
$result= curl_exec ($ch);
if(curl_error($ch))
print "Error processing request";
curl_close ($ch);
if ($result=='ok')
{
$dbc = mysql_connect($host,$user,$pass) or die("DB conection error");
mysql_select_db($db,$dbc);
if(!(empty($name)))
{
$sql = "UPDATE `accounts` SET `premium_points` = `premium_points` + $puntos WHERE `name` = \"".$name."\"";
$res = mysql_query($sql,$dbc);
if(mysql_affected_rows() == 0)
{
die('This username does not exist: <font color="blue">'.$name.'</font>');
}
die("Codigo : $codigo ok , Points added to your account");
}
else {
die('You did not set the user!');
}
}
if ($result=='no')
{
die('This code is already in used');
}
}
if ($_GET['key']!=$key)
{
die('Acceso no permitido');
}
if(!(empty($name))){
$sql = "UPDATE `accounts` SET `premium_points` = `premium_points` + $puntos WHERE `name` = \"".$name."\"";
$res = mysql_query($sql,$dbc);
if(mysql_affected_rows() == 0)
die('This username does not exist: '.$name.'');
}
else
die('You did not set the user!');
die ('ok');
?>