thats the full code of my page:
=substr(===explode(=$st1date[2].= mssql_init(=mssql_execute($stmt);
<tr><td ><img src='images/sqlerror.png' width='64' height='64' /></td><td align='center'><blink>" . mssql_get_last_message() . "<br /><strong>PLEASE REPORT THE ABOVE ISSUE TO YOUR ADMIN TEAM</strong></blink></td><td><img src='images/sqlerror.png' width='64' height='64' /></tr></table>";
exit();
}
//*******************
//New offence code below
if (isset($_REQUEST['offenses']) )
{
$v = unserialize(urldecode(stripslashes(($offenses[0]))));
$q=0;
foreach ($v as $a)
{
if($q==0)
{
if($originalfirstoffence != $a)
{
$stmt= mssql_init("sp_remOffCase");
mssql_bind($stmt, '@id', $originalfirstoffenceid, SQLINT4,false,false,10);
mssql_execute($stmt);
}
}
if (!is_null($a))
{
$stmt= mssql_init("sp_InsertOffenceCase");
mssql_bind($stmt, '@offence', $a, SQLVARCHAR,false,false,30);
mssql_bind($stmt, '@offenderid',$offenderid,SQLINT4,false,false,10);
mssql_bind($stmt, '@caseid',$vrecid,SQLVARCHAR,false,false,50);
$tmp9=mssql_execute($stmt);
$q++;
if (!$tmp9)
{
echo "<table><tr><td ><img src='images/sqlerror.png' width='64' height='64' /></td><td align='center'><blink>" . mssql_get_last_message() . "<br /><strong>PLEASE REPORT THE ABOVE ISSUE TO YOUR ADMIN TEAM</strong></blink></td><td><img src='images/sqlerror.png' width='64' height='64' /></tr></table>";
exit();
}
}
}
}
//End of new offence code
//*******************
}
//$sel2="select * from ".VICTIM." where id='$vrecid'";
//$res2=mssql_query($sel2);
//$rec2=mssql_fetch_array($res2);
$stmt=mssql_init("sp_GetLastPageVictim");
mssql_bind($stmt,'@id',$vrecid,SQLINT4,false,false,10);
$res2=mssql_execute($stmt);
if (!$res2)
{
echo "<table><tr><td ><img src='images/sqlerror.png' width='64' height='64' /></td><td align='center'><blink>" . mssql_get_last_message() . "<br /><strong>PLEASE REPORT THE ABOVE ISSUE TO YOUR ADMIN TEAM</strong></blink></td><td><img src='images/sqlerror.png' width='64' height='64' /></tr></table>";
exit();
}
$rec2=mssql_fetch_array($res2);
//echo mssql_get_last_message();
//echo $rec2['contactvcr'];
//echo $rec2['contactvcr'];
//echo $rec2['status'];
$selectliasion="select * from ".STAFF." where id='$rec2[addedby]'";
$resultliasion=mssql_query($selectliasion);
$recordliasion=mssql_fetch_array($resultliasion);
?>
<div style="display:none"><input type="text" id="pageno" name="pageno" value="3" /></div>
<input type="hidden" id="vrecid" name="vrecid" value="<?=$vrecid;?>" />
<input type="hidden" id="vicid" name="vicid" value="<?=$vicid;?>" />
<table width="100%" cellspacing="0" cellpadding="0">
<tr>
<td bgcolor="#ffffff" align="center" valign="top">
<table width="750" border="0" cellspacing="0" cellpadding="0">
<tr>
<td valign="top"><table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td valign="top">
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td colspan="3" valign="top"></td>
</tr>
<tr>
<td colspan="3"><table width="100%" cellpadding="0" cellspacing="0"><tr>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="121" height="30" background="images/000.jpg" class="style7" style="padding-left:10px;"> </td>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="157" background="images/001.jpg" class="style7" style="padding-left:10px;"> </td>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="63" background="images/000.jpg" class="style7" style="padding-left:10px;" > </td>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="103" background="images/001.jpg" class="style7" style="padding-left:10px;"></td>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="108" background="images/000.jpg" class="style7" style="padding-left:10px;"> </td> <td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
<td width="136" background="images/001.jpg" class="style7" style="padding-left:10px;"> </td>
<td width="1" background="images/line4.jpg" ><img src="images/line4.jpg" width="1" height="25" /></td>
</tr></table></td>
</tr>
<tr>
<td colspan="3"><table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="1" background="images/loginline1.jpg"></td>
<td height="180" valign="top" bgcolor="#fafafa">
<input name="rand_record_id" id="rand_record_id" type="hidden" value="<?php echo $rec2['recordid'];?>" />
<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="4"> </td>
<td width="10" class="style5"> </td>
<td width="730" class="style5"> </td>
<td width="4"> </td>
</tr>
<tr>
<td> </td>
<td> </td>
<td><table width="100%" border="0" cellspacing="0" cellpadding="3">
<tr>
<td height="30" colspan="4" align="left" class="style3" style="color:#000000">OTHER INFORMATION </td>
</tr>
<tr>
<td width="138" height="30" align="left" class="style31" >Case Notes</td>
<td width="214" align="left"><br>
<textarea id="notes" name="fixlength" maxlength="300" lengthcut="true" rows="5" cols="45">=''</textarea>
</p>
<label></label>
<script type="text/javascript" language="javascript" src="/js/charcount.js"></script>
</td>
<td width="175" height="30" align="left" class="style31" >Status</td>
<td width="179" align="left"><select id="status" name="status" style="width:150px;" title="Status">
<option value="">Select</option>
<option value="Active" <? if($rec2['status']=='Active') {?> selected="selected" >Active </option>
<option value="Closed" <? if($rec2['status']=='Closed') {?> selected="selected" >Closed </option>
<option value="Discretionary" <? if($rec2['status']=='Discretionary') {?> selected="selected" >Discretionary </option>
<option value="Gutted" <? if($rec2['status']=='Gutted') {?> selected="selected" >Gutted </option>
<option value="Inactive" <? if($rec2['status']=='Inactive') {?> selected="selected" >Inactive </option>
<option value="Open" <? if($rec2['status']=='Open') {?> selected="selected" >Open</option>
<option value="Pending" <? if($rec2['status']=='Pending') {?> selected="selected" >Pending </option>
</select></td>
</tr>
</table></td>
<td> </td>
</tr>
<tr>
<td> </td>
<td align="right"></td>
<td align="right"><table width="65%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="302" class="style31" align="center">Save the case to return to a blank front sheet </td>
<td width="94"><input name="submit4" type="submit" value="Save" title="Save" onClick="workisdone=true;" style="background:url(images/button.png); border:none; height:35px; width:198px; font-size:14px; font-weight:bold" /></td>
<td width="11"> </td>
</tr>
</table></td>
<td> </td>
</tr>
<tr><td colspan="4" style="font-size:9px;"> </td></tr>
</table> </td>
<td width="1" background="images/loginline1.jpg" align="right"></td>
</tr>
<tr>
<td colspan="3" background="images/loginline2.jpg"><img src="images/loginline2.jpg" width="4" height="1" /></td>
</tr>
</table></td>
</tr>
</table></td>
</tr>
</table></td>
</tr>
</table>
</td>
</tr>
<tr>
<td height="74" background="images/footerbg.jpg" align="left">
<input type="button" id="submit" name="submit" style="background:url(images/leftarrow.png); border:none; width:32px; height:32px; cursor:pointer;" title="Previous" value="" onclick=' validate5()' /></td>
</tr>
</table>
<script type="text/javascript">
function addmoreprisonname()
{
var frm_obj = window.document.victim;
var tbody = document.getElementById("table1").getElementsByTagName("tbody")[2];
var nUploads = parseInt(frm_obj.noofrows.value);
var row1 = document.createElement("TR");
var cell3 = document.createElement("TD");
cell3.setAttribute("align","center");
var cell2 = document.createElement("TD");
cell2.setAttribute("align","left");
var eInput1 = document.createElement("input");
eInput1.setAttribute("type","text");
eInput1.setAttribute("name","prisonname[]");
eInput1.setAttribute("id","prisonname_"+nUploads);
cell2.appendChild(eInput1);
var img = document.createElement("img");
img.setAttribute("src","images/delete.png");
img.setAttribute("style","cursor:hand; !important; cursor:pointer; !important; position: relative;padding-left:2px;");
img.setAttribute("alt","Remove this Image");
img.setAttribute("title","Remove this Image");
img.onclick = function() { removetr(row1,nUploads); }
cell2.appendChild(img);
row1.appendChild(cell3);
row1.appendChild(cell2);
tbody.appendChild(row1);
frm_obj.noofrows.value = nUploads+1;
}
function removetr(row1)
{
row1.parentNode.removeChild(row1);
document.getElementById("noofrows").value = document.getElementById("noofrows").value - 1;
document.getElementByid('removedrows').value=document.getElementByid('removedrows').value+",";
}
function addmorevictimtelephone()
{
var frm_obj = window.document.victim;
var tbody = document.getElementById("table1").getElementsByTagName("tbody")[1];
var nUploads = parseInt(frm_obj.noofrows1.value);
var row1 = document.createElement("TR");
var cell3 = document.createElement("TD");
cell3.setAttribute("align","center");
cell3.setAttribute("colspan","3");
var cell2 = document.createElement("TD");
cell2.setAttribute("align","left");
var eInput1 = document.createElement("input");
eInput1.setAttribute("type","text");
eInput1.setAttribute("name","victimtelephone[]");
eInput1.setAttribute("id","victimtelephone_"+nUploads);
cell2.appendChild(eInput1);
var img = document.createElement("img");
img.setAttribute("src","images/delete.png");
img.setAttribute("style","cursor:hand; !important; cursor:pointer; !important; position: relative;padding-left:2px;");
img.setAttribute("alt","Remove this Image");
img.setAttribute("title","Remove this Image");
img.onclick = function() { removetrvictimtelephone(row1,nUploads); }
cell2.appendChild(img);
row1.appendChild(cell3);
row1.appendChild(cell2);
tbody.appendChild(row1);
frm_obj.noofrows.value = nUploads+1;
}
function removetrvictimtelephone(row1)
{
row1.parentNode.removeChild(row1);
document.getElementById("noofrows1").value = document.getElementById("noofrows1").value - 1;
document.getElementByid('removedrows1').value=document.getElementByid('removedrows1').value+",";
}
function addmoreoffenses()
{
var frm_obj = window.document.victim;
var tbody = document.getElementById("table2").getElementsByTagName("tbody")[1];
var nUploads = parseInt(frm_obj.noofrows2.value);
var row1 = document.createElement("TR");
var cell3 = document.createElement("TD");
cell3.setAttribute("align","center");
cell3.setAttribute("colspan","1");
var cell2 = document.createElement("TD");
cell2.setAttribute("align","left");
var eInput1 = document.createElement("input");
eInput1.setAttribute("type","text");
eInput1.setAttribute("name","offenses[]");
eInput1.setAttribute("id","offenses_"+nUploads);
cell2.appendChild(eInput1);
var img = document.createElement("img");
img.setAttribute("src","images/delete.png");
img.setAttribute("style","cursor:hand; !important; cursor:pointer; !important; position: relative;padding-left:2px;");
img.setAttribute("alt","Remove this Image");
img.setAttribute("title","Remove this Image");
img.onclick = function() { removetrvictimtelephone(row1,nUploads); }
cell2.appendChild(img);
row1.appendChild(cell3);
row1.appendChild(cell2);
tbody.appendChild(row1);
frm_obj.noofrows.value = nUploads+1;
}
function removetroffenses(row1)
{
row1.parentNode.removeChild(row1);
document.getElementById("noofrows2").value = document.getElementById("noofrows2").value - 1;
document.getElementByid('removedrows2').value=document.getElementByid('removedrows2').value+",";
}
function addmorelinkedto()
{
var frm_obj = window.document.victim;
var tbody = document.getElementById("table3").getElementsByTagName("tbody")[1];
var nUploads = parseInt(frm_obj.noofrows3.value);
var row1 = document.createElement("TR");
var cell5 = document.createElement("TD");
cell5.setAttribute("align","center");
cell5.setAttribute("colspan","1");
var cell3 = document.createElement("TD");
cell3.setAttribute("align","center");
cell3.setAttribute("colspan","1");
var cell2 = document.createElement("TD");
cell2.setAttribute("align","left");
var eInput1 = document.createElement("input");
eInput1.setAttribute("type","text");
eInput1.setAttribute("name","linkedto[]");
eInput1.setAttribute("id","linkedto_"+nUploads);
cell2.appendChild(eInput1);
var img = document.createElement("img");
img.setAttribute("src","images/delete.png");
img.setAttribute("style","cursor:hand; !important; cursor:pointer; !important; position: relative;padding-left:2px;");
img.setAttribute("alt","Remove this Image");
img.setAttribute("title","Remove this Image");
img.onclick = function() { removetrvictimtelephone(row1,nUploads); }
cell2.appendChild(img);
var cell4= document.createElement("TD");
cell4.setAttribute("align","left");
var eInput2 = document.createElement("input");
eInput2.setAttribute("type","text");
eInput2.setAttribute("name","caseno[]");
eInput2.setAttribute("id","caseno_"+nUploads);
cell4.appendChild(eInput2);
row1.appendChild(cell5);
row1.appendChild(cell2);
row1.appendChild(cell3);
row1.appendChild(cell4);
tbody.appendChild(row1);
frm_obj.noofrows.value = nUploads+1;
}
function removetrlinkedto(row1)
{
row1.parentNode.removeChild(row1);
document.getElementById("noofrows3").value = document.getElementById("noofrows3").value - 1;
document.getElementByid('removedrows3').value=document.getElementByid('removedrows3').value+",";
}
</script>