i made xhytml passed thats easy as pie

<?php include('../core/main.inc'); header_type(); cleardata(); if(ipbanned(ip(),browser())){ if(!shield(getuid_sid($sid))){ echo head_tag("Ip Blocked!!!",0,0); echo ipbanned_msg(); echo foot_tag(); exit(); } } if(!islogged($sid)){ echo head_tag("Error!!!",0,0); echo session_expired(); echo foot_tag(); exit(); } if(banned(getuid_sid($sid))){ echo head_tag("Error!!!",1,getnick_sid($sid)); echo banned_msg($sid); echo foot_tag(); exit(); } mysql_query("UPDATE users SET browser='".browser()."', ipaddress='".ip()."', host='".subno()."' WHERE id='".getuid_sid($sid)."'"); /////////////////////////////GALLERY///////////////////////////// addonline(getuid_sid($sid),"Viewing Gallery",""); echo head_tag(getnick_sid($sid)."@Gallery",1,getnick_sid($sid)); $title="<img src=\"../images/male.gif\" alt=\"\"/><img src=\"../images/female.gif\" alt=\"\"/> [u][i][b]Gallery Pics[/b][/i][/u]"; $main="<p align=\"center\">\n"; $items_per_page="5"; if(!isset($page)){$page=0;} $total=0; if(!($dp=opendir("./"))) die ("Cannot open ./"); $file_array=array(); while($file=readdir($dp)){ if(substr($file,0,1)!='.' and $file!="gallery.php" and $file!="upload.php"){$file_array[]=$file;} } $file_count=count($file_array); sort($file_array); if($file_count>0){ $first_record = $page * $items_per_page; $last_record = $first_record + $items_per_page; while(list($fileIndexValue, $file_name)=each($file_array)){ if(($fileIndexValue>=$first_record)AND($fileIndexValue<$last_record)){ $pic=explode(".",$file_name); $nick=explode("(",$file_name); $sex=mysql_fetch_array(mysql_query("SELECT sex FROM profiles WHERE uid='".getuid_nick($nick[0])."'")); if($sex[0]=="M"){$sex="<img src=\"../images/male.gif\" alt=\"(M)\"/>";$style=" style=\"color:#0000FF\"";} if($sex[0]=="F"){$sex="<img src=\"../images/female.gif\" alt=\"(F)\"/>";$style=" style=\"color:#FF0066\"";} if((getnick_sid($sid)==$nick[0])||(delpics(getuid_sid($sid)))){ $main.="<img src=\"../phpThumb/phpThumb.php?src=../gallery/$file_name&w=150&f=$pic[1]&sia=$nick[0]\" alt=\"$pic[0]\"/> $sex<a href=\"./$file_name\"$style>$pic[0]</a> ".round(filesize($file_name)/1024,1)."kb <a href=\"./gallery.php?page=$page&sid=$sid&delete=$file_name\"><img src=\"../images/error.gif\" alt=\"[x]\"/></a> \n"; }else{ $main.="<img src=\"../phpThumb/phpThumb.php?src=../gallery/$file_name&w=150\" alt=\"$pic[0]\"/> $sex<a href=\"./$file_name\"$style>$pic[0]</a> ".round(filesize($file_name)/1024,1)."kb \n"; } if($delete==$file_name){ if((getnick_sid($sid)==$nick[0])||(delpics(getuid_sid($sid)))){ unlink("./$file_name"); $main.=" $file_name deleted successfully <meta http-equiv=Refresh content=1;url=./gallery.php?page=$page&sid=$sid>\n"; echo xhtml($sid,$title,0,0,0,0,0,0,0,0,0,$main); echo foot_tag(); exit; } } $total=$total+filesize($file_name); } } $pages=(int)ceil($file_count/$items_per_page); $pages=($pages-1); if(($file_count>0)AND($page!=0)){ $main.="<a href=\"".$_SERVER["PHP_SELF"]."?action=pics&page=".($page-1)."&sid=$sid&script=$script\"><img src=\"../images/prev.gif\" alt=\"Prev\"/></a> |"; } if(($file_count >0)AND($last_record < $file_count)){ $main.=" <a href=\"".$_SERVER["PHP_SELF"]."?action=pics&page=".($page+1)."&sid=$sid&script=$script\"><img src=\"../images/next.gif\" alt=\"Next\"/></a>\n"; } $main.=" Directory: $file_count "; if($file_count==1){$main.="file";} else{$main.="files";} } $main.=" <a href=\"./upload.php?sid=$sid\">Upload</a> \n"; closedir($dp); $main.="</p>\n"; $L1="<- <a href=\"../main.php?sid=$sid\"><img src=\"../images/home.gif\" alt=\"\"/>Main Menu</a>"; echo xhtml($sid,$title,1,$L1,0,0,0,0,0,0,0,$main); echo foot_tag(); ?>
<?php include('../core/main.inc'); header_type(); cleardata(); if(ipbanned(ip(),browser())){ if(!shield(getuid_sid($sid))){ echo head_tag("Ip Blocked!!!",0,0); echo ipbanned_msg(); echo foot_tag(); exit(); } } if(!islogged($sid)){ echo head_tag("Error!!!",0,0); echo session_expired(); echo foot_tag(); exit(); } if(banned(getuid_sid($sid))){ echo head_tag("Error!!!",1,getnick_sid($sid)); echo banned_msg($sid); echo foot_tag(); exit(); } mysql_query("UPDATE users SET browser='".browser()."', ipaddress='".ip()."', host='".subno()."' WHERE id='".getuid_sid($sid)."'"); /////////////////////////////GALLERY///////////////////////////// addonline(getuid_sid($sid),"Uploading Pic",""); echo head_tag(getnick_sid($sid)."@Gallery",1,getnick_sid($sid)); $title="[u][i][b]Upload[/b][/i][/u] "; $main="<p align=\"center\"> Image Files \n"; $size_bytes=2048000; $kb=$size_bytes/1024; $mb=$kb/1024; $main.="Max [b]$mb[/b] Mb <img src=\"../images/point.gif\" alt=\"!\"/>You can email ur pic to [b]afta_drk@hotmail.com[/b] wif ur username attached or use the below uploader </p> <div class=\"center\"> <form method=\"post\" enctype=\"multipart/form-data\" action=\"./upload.php?upload=yes&sid=$sid\"> <input type=\"file\" name=\"filetoupload\"/> <input type=\"submit\" name=\"uploadform\" value=\"Upload\"/> </form> </div> <p align=\"center\">\n"; $extlimit="yes"; $limitedext=array(".jpg",".jpeg",".gif",".png"); $ext=strtolower(strrchr($_FILES['filetoupload'][name],'.')); $file_type=$_FILES['filetoupload']['type']; $file_name=$_FILES['filetoupload']['name']; $file_size=$_FILES['filetoupload']['size']; $file_tmp=$_FILES['filetoupload']['tmp_name']; if($upload=="yes"){ if(!is_uploaded_file($_FILES['filetoupload']['tmp_name'])){ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/>No file selected! <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else if($extlimit=="yes" && !in_array($ext,$limitedext)){ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/>Invalid file type! <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else if($file_size>$size_bytes){ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/>Exceeded File size limit! Maximum [b]$kb[/b] Kb. <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else if(file_exists("./$file_name")){ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/>Filename already exists! <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else if(file_exists("./".getnick_sid($sid)."(5)".$ext)){ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/> [b]Error!!![/b] 5 pics hav already been uploaded... <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else if($file_size){ if(!file_exists("./".getnick_sid($sid)."(1)".$ext)){$pic=getnick_sid($sid)."(1)".$ext;} if(file_exists("./$pic")){$pic=getnick_sid($sid)."(2)".$ext;} if(file_exists("./$pic")){$pic=getnick_sid($sid)."(3)".$ext;} if(file_exists("./$pic")){$pic=getnick_sid($sid)."(4)".$ext;} if(file_exists("./$pic")){$pic=getnick_sid($sid)."(5)".$ext;} move_uploaded_file($file_tmp, "./$pic"); $main.=" <img src=\"../phpThumb/phpThumb.php?src=../gallery/$pic&w=150\" alt=\"$pic\"/> <img src=\"../images/ok.gif\" alt=\":o)\"/> $file_name sucessfully uploaded! <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } else{ $main.="<img src=\"../images/error.gif\" alt=\"[x]\"/>Unknown error! Pls try again... <a href=\"./gallery.php?sid=$sid\">Gallery Pics</a>\n"; } } $main.="</p>\n"; $L1="<- <a href=\"../main.php?sid=$sid\"><img src=\"../images/home.gif\" alt=\"\"/>Main Menu</a>"; echo xhtml($sid,$title,1,$L1,0,0,0,0,0,0,0,$main); echo foot_tag(); ?>
Comment