<?php

function inject_check($sql_str)
{
  return eregi('select|insert|update|delete|\'|\/\*|\*|\.\.\/|\.\/|union|into|load_file|outfile', $sql_str); // 進行過濾
}

function check_input($value)
{
// 去除斜杠
if (get_magic_quotes_gpc())
  {
  $value = stripslashes($value) ;
  }
// 如果不是數字則加引號
if (!is_numeric($value))
  {
  $value = "'" . mysql_real_escape_string($value) . "'";
  }
return $value;
}
?>



<html>

<head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <title>解題列表</title>
    <link rel="stylesheet" href="../../assets/css/main.css" />
    <style>
        a {
            text-decoration: none
        }

    </style>

    <style type="text/css">
        < !-- a:hover {
            position: relative;
            top: 1px;
            left: 1px;
        }

        -->

    </style>

</head>

<body background="images/background.gif">

    <Script Language="JavaScript">
        function pop_code(strURL, strWinname, strFeatures) {
            var strFeatures = "left=80,screenX=0,top=80,screenY=10";

            var maxh = screen.availHeight - 100;
            var maxw = screen.availWidth - 20;

            strFeatures += ",height=" + maxh;
            strFeatures += ",innerHeight=" + maxh;
            strFeatures += ",width=" + maxw;
            strFeatures += ",innerWidth=" + maxw;
            strFeatures += ",scrollbars=no";
            strFeatures += ",resizable=yes";
            strFeatures += ",status=yes";
            window.remoteWindow = window.open(strURL, strWinname, strFeatures);
            window.remoteWindow.window.focus();
        }

    </Script>


    <div class="row">
        <div class="col-12">

            <!-- Table -->
            <section class="box" style="padding-top:0.5em;">
                <div class="table-wrapper">
                    <table>

                        <?php

include('register_globals.php');
register_globals();

if (inject_check($user_id))
{
        echo '驗證失敗';
        exit();
}
else
{

    include ("config.php");
	  $user_id = check_input($user_id);	
	
//    $query_select = "select * from $studenttable where user_id='$user_id'";
    $query_select = "select * from $studenttable where user_id=$user_id";
    
    $result = mysql_query($query_select,$link);
    $row = mysql_fetch_row($result);
    list($user_id,$passwd,$chinesename,$register_year,$acm_total_solved,$honor,$usaco_total_solved,$zero_total_solved,$tioj_total_solved,$poj_total_solved,$green_total_solved,$hdu_total_solved,$toj_total_solved,$codeforces_total_solved,$csacademy_total_solved,$atcoder_total_solved,$spoj_total_solved,$icpc_total_solved) = $row;
    $year=substr($register_year,0,4);
    echo "<tr>$chinesename</tr>";
    echo "<tr>　</tr>";
    echo "<tr>　高中生程式解題系統解題數：$zero_total_solved</tr>";

	$query_select = "select * from $programtable where user_id='$user_id' and type=3 order by zero_prob_name";
	$result = mysql_query($query_select,$link);
	$num=0;
  	while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$zero_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
	}
}


?>
                    <br />

                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php

  echo "<tr>　台中女中程式解題系統：$green_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=6 order by green_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$green_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />

                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php

  echo "<tr>　Uva(ACM)解題數：$acm_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=1 order by acm_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$acm_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>
                    </table>

                    <br />
                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　POJ解題數：$poj_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=5 order by poj_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$poj_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />

                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　HDU解題數：$hdu_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=7 order by hdu_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$hdu_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />

                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　TOJ解題數：$toj_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=8 order by toj_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$toj_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />


                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　TIOJ解題數：$tioj_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=4 order by tioj_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$tioj_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />

                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　Codeforces解題數：$codeforces_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=9 order by codeforces_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$codeforces_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />
                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　CS Academy解題數：$csacademy_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=10 order by csacademy_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$csacademy_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />
                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　AtCoder解題數：$atcoder_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=11 order by atcoder_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$atcoder_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />
                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　SPOJ解題數：$spoj_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=12 order by spoj_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$spoj_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>

                    <br />
                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　競程日記OJ解題數：$icpc_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=13 order by icpc_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
        if ($num%10==0)
          echo "<tr>";
        echo "<td width=\"10%\" align=\"center\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$icpc_prob_name</a></font></td>";

        if ($num%10==9)
             echo "</tr>";
        $num++;
  }
?>
                    <br />


                    <table border="0" cellpadding="5" bordercolor="#000080" cellspacing="0" style="border-collapse: collapse" width="75%">
                        <?php


  echo "<tr>　USACO解題數：$usaco_total_solved</tr>";

  $query_select = "select * from $programtable where user_id='$user_id' and type=2 order by usaco_prob_name";
  $result = mysql_query($query_select,$link);
  $num=0;
  while ($row = mysql_fetch_row($result)) {
        list($id,$user_id,$acm_prob_name,$code,$type,$usaco_prob_name,$zero_prob_name,$tioj_prob_name,$poj_prob_name,$green_prob_name,$hdu_prob_name,$toj_prob_name,$codeforces_prob_name,$csacademy_prob_name,$atcoder_prob_name,$spoj_prob_name,$icpc_prob_name) = $row;
      if ($num%5==0)
      {
        echo "<tr>";
        echo "<td>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td>";
      }
      echo "<td width=\"20%\" align=\"left\"><font color=\"#000080\"><a href=\"javascript:pop_code('code.php?id=$id','remoteWindow','')\">$usaco_prob_name</a></font></td>";
      if ($num%5==4)
           echo "</tr>";
      $num++;
  }
?>
                    </table>
                </div>
            </section>

        </div>
    </div>

</body>

</html>
