if (!isset($_REQUEST['accept'])): ?>
=$copy->body?>
else:
$allowed_args = ',handle,email,firstname,lastname,phone,property,downpayment,experience,accept,';
foreach(array_keys($_REQUEST) as $k) {
$temp = ",$k,";
if(strpos($allowed_args,$temp) !== false) {$$k = mysql_real_escape_string($_REQUEST[$k]);}
}
$downpayment = str_replace(array('$',','), '', $downpayment);
// check for existing user
$checkquery = "SELECT COUNT(*) FROM user WHERE handle = '$_REQUEST[handle]'";
$checkresult = mysql_query($checkquery);
if(mysql_result($checkresult,0,0)==0 && $_SERVER['REQUEST_METHOD'] == "POST" && is_valid_email($_REQUEST['email'])) {
//send email
$password = substr(md5(time()),0,8);
$subject = "New user... $firstname $lastname";
$body = "A new account has been set up for:
user: $handle
password: $password";
contains_bad_str($email);
contains_bad_str($body);
contains_newlines($email);
$headers = "From: ".EMAIL_FROM;
mail(EMAIL_TO, $subject, $body, $headers);
// insert into db
$sql = "INSERT INTO user SET
handle = '$handle',
password = AES_ENCRYPT('$password','aA'),
firstname = '$firstname',
lastname = '$lastname',
email = '$email',
phone = '$phone',
property = '$property',
downpayment = '$downpayment',
experience = '$experience'";
if (mysql_query($sql)) {} else {echo 'Unable to process your request. Please try again later.';}
?>
=$copy->sectionone?>
} else { ?>
This user already exists. Please try another user name.
} endif; ?>