include("incs/colLeft.php") ?>
include("incs/nav2_resources.php") ?>
iag | job listings
mysql_connect("mysql-3",$dbuser,$dbpass);
mysql_select_db($dbname) or die("Unable to select database.");
if ($submit) {
$legitmember = 0;
// first we clean our inputs, because this query accesses somewhat sensitive data, and we dont like injection attacks
$uid = mysql_safe($_POST["uid"]);
$uid = "8".$uid;
$lname = mysql_safe($_POST["lname"]);
$netid = mysql_safe($_POST["netid"]);
$query_memcheck = "SELECT * FROM user_data WHERE PAID='TRUE' AND UID='$uid' AND netid='$netid' AND lname='$lname'";
$result = mysql_query($query_memcheck);
while($row = mysql_fetch_row($result)) {
$legitmember = 1;
}
if ($legitmember == 1) {
$query2 = "SELECT name,description,added_date FROM joblist_data WHERE active='1' AND private_job='TRUE' ORDER BY added_date DESC";
$result2 = mysql_query($query2);
echo "
IAG Exclusive Listings
";
while($row = mysql_fetch_row($result2)) {
$joshname = $row[0];
$joshdesc = $row[1];
$joshadded = $row[2];
echo "
".$joshname."
";
echo "Added: ".date("F j, Y",strtotime($joshadded))."
";
echo "
".$joshdesc."
";
}
}
else {
echo "
Failed logon attempt. Please retry.
";
echo $loginform;
}
}
else {
echo $loginform;
}
$query = "SELECT name,description,added_date FROM joblist_data WHERE active='1' AND private_job='FALSE' ORDER BY added_date DESC";
$result = mysql_query($query);
echo "
Public Listings
";
while($row = mysql_fetch_row($result)) {
$joshname = $row[0];
$joshdesc = $row[1];
$joshadded = $row[2];
echo "
".$joshname."
";
echo "Added: ".date("F j, Y",strtotime($joshadded))."
";
echo "
".$joshdesc."
";
}
mysql_close();
?>
include("incs/colRight.php") ?>
include("incs/footer.php") ?>