Hi, Thanks for your reply but that didn't solve the problem.. I'll post all that pages code up:
<?php
include("top.php");
if($_SESSION['id']){
if($_GET['msgid']){
$id = mysql_real_escape_string($_GET['msgid']);
$channelnames = mysql_real_escape_string($_GET['channelnames']);
echo "<table border=0 width=749 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3></td><td><a href=\"messages.php\"><b><- Back To Messages</b></a><br>";
$ga = mysql_query("SELECT * FROM `accounts` WHERE `name`='".getID($name)."'") or die(mysql_error());
$a = mysql_fetch_array($ga);
if($a['gm']=="1"){
echo "| <a href=\"members.php?name=".$name."&page=gmblog\">GM Blog</a>";
}
echo "</center>";
// Delete Message
}elseif($_GET['action']=="content"){
// Display Message Content
}else{
$gc = mysql_query("SELECT * FROM `messages` WHERE `id`='".$id."'") or die(mysql_error());
$a = mysql_fetch_array($gc);
$av = mysql_query("UPDATE `messages` SET `new` = 0 WHERE `reciever`='".getDName()."'") or die(mysql_error());
echo "<br><fieldset><legend>Unique Message ID - ".$a['id']."</legend><b>Sender:</b> ".$a['sender']." - <b>Date Sent:</b> ".$a['sent_date']."<br /></fieldset><fieldset><b>Subject:</b> ".$a['subject']."<br /><b>Message</b><br>".$a['body']."<br /><hr><a href=sendmsg.php><b>Reply To This Message | <a href=\"deletemsg.php\">Delete This Message</a><br></b></a></font>\n</td>";
echo "</fieldset></td></tr></table><br>";
}
// Send Messages
}elseif($_GET['action']=="send"){
$id = mysql_real_escape_string($_GET['id']);
$gn = mysql_query("SELECT * FROM `messages`") or die(mysql_error());
$gc = mysql_query("SELECT * FROM `messages` WHERE `raid`='".$_SESSION['id']."' ORDER BY `id` DESC") or die(mysql_error());
echo "<table border=0 width=739 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td></td></tr>";
echo "<tr><td width=\"150\"><b><a href=\"messages.php\"><- Back To Messages</a></b></td><td width=\"500\"></td><td width=\"150\"><b><a href=\"messages.php?action=delete\">Delete A Message -></a></b></td></tr><tr></table><form method=\"POST\">";
echo "<table border=0 width=739 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td>";
echo "<fieldset><legend>Send Message</legend><table border=0 width=739 cellspacing=0 cellpadding=0 align=center><tr><td width=6 rowspan=3> </td><td>";
echo "</select></td></tr>";
echo "<tr>Here you can send messages to other members on this website.<br><br>";
echo "<td></td><td><b>Subject:</b><input type=\"text\" name=\"subject\" maxlength=\"20\"><font color=white>______________..</font> <b>Send To:</b>
<select name=\"reciever\">";
echo "<option value=\"\">Please Select..</option>";
$gn = mysql_query("SELECT * FROM `accounts` ORDER BY `profile_name` DESC") or die(mysql_error());
while($n = mysql_fetch_array($gn)){
echo "<option value=\"".$n['profile_name']."\">".$n['profile_name']."</option>";
}
echo "</select>";
echo "<br><br><b>Msg Body:</b><br /><textarea name=\"text\" style=\"height:200px;width:500px;\"></textarea><br>";
echo "<input type=\"submit\" name=\"sendmsg\" value=\"Send Message!\" style=\"width:500px;\"></td></tr>";
echo "</td></tr></table>";
if($_POST['sendmsg']){
$subject = mysql_real_escape_string($_POST['subject']);
$reciever = mysql_real_escape_string($_POST['reciever']);
$text = htmlspecialchars(mysql_real_escape_string($_POST['text']));
$said = htmlspecialchars(mysql_real_escape_string($_POST['said']));
$id = htmlspecialchars(mysql_real_escape_string($_POST['id']));
$sender = htmlspecialchars(mysql_real_escape_string($_POST['sender']));
$ucheck = mysql_query("SELECT `profile_name` FROM `tblclients` WHERE `profile_name`='".$reciever."'") or die(mysql_error());
if($text == ""){
echo "You cannot leave the comment field blank!";
}elseif($subject == ""){
echo "You cannot leave the subject field blank!";
}else{
$raid = mysql_query("SELECT `id` FROM `accounts` WHERE `profile_name`='".$reciever."'") or die(mysql_error());
while($c = mysql_fetch_array($raid)){
$i = mysql_query("INSERT INTO `messages` (`subject`,`sender`,`reciever`,`body`,`said`,`raid`) VALUES ('".$subject."','".getDName()."','".$reciever."','".$text."','".$_SESSION['id']."','".$c['id']."')") or die(mysql_error());
echo "<br><b>Your message has been sent to <b>".$reciever."</b> sucessfully!</b><br><br>";
}
echo "</table></center>";
echo "</form></fieldset>";
echo "</table>";
echo "</fieldset>";
}
}
// Delete Message
}elseif($_GET['action']=="delete"){
echo "<table border=0 width=739 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td></td></tr>";
echo "<tr><td width=\"150\"><b><a href=\"messages.php\"><- Back To Messages</a></b></td><td width=\"500\"></td><td width=\"150\"><b><a href=\"messages.php?action=send\">Send A Message -></a></b></td></tr><tr></table><br><br>";
echo "<table border=0 width=753 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td>";
echo "<fieldset><legend><b>Delete A Message</b></legend>";
if(!$_POST['del']){
echo "<form method=\"POST\">";
echo "<center><table border=\"0\">";
echo "<tr><td align=\"right\"><b>MSG Subject:</b></td><td><select name=\"sub\">";
echo "<option value=\"\">Please Select..</option>";
$gn = mysql_query("SELECT * FROM `messages` WHERE `raid`='".$_SESSION['id']."' ORDER BY `id` DESC") or die(mysql_error());
while($n = mysql_fetch_array($gn)){
echo "<option value=\"".$n['id']."\">#".$n['id']." - ".$n['subject']." - ".$n['sender']."</option>";
}
echo "</select></td></tr>";
echo "<tr><td align=\"right\"><b>Delete?</b></td><td><select name=\"dec\">";
echo "<option value=\"0\">No</option>";
echo "<option value=\"1\">Yes</option>";
echo "</select></td></tr>";
echo "<tr><td></td><td><input type=\"submit\" name=\"del\" value=\"Delete\"></td></tr>";
echo "</table></center>";
echo "</form>";
}else{
$sub = mysql_real_escape_string($_POST['sub']);
$dec = mysql_real_escape_string($_POST['dec']);
if($sub == ""){
echo "Please select a message to delete!";
}elseif($dec == "0"){
echo "You selected \"No\". Delete unsuccesful!";
}else{
$d = mysql_query("DELETE FROM `messages` WHERE `id`='".$sub."'") or die(mysql_error());
echo "The message <b>".$n['subject']."</b> has been deleted from your messages!";
}
}
echo "</fieldset></td></tr></table>";
}else{
//Display List Messages
echo "<table border=0 width=749 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td>";
$gc = mysql_query("SELECT * FROM `messages` WHERE `reciever`='".getDName()."'") or die(mysql_error());
$m = mysql_fetch_array($gc);
echo "<table width=\"753\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\"><tr><td width=\"453\"><b>Welcome To The Message Center, ".getDName()."..</b></td><td width=\"300\"><a href=\"messages.php?action=delete\"><b><- Delete Message</b></a><font color=white>____</font><a href=\"messages.php?action=send\"><b>Send Message -></b></a></td></tr></table><br>";
echo "Select one of the message titles to view the message.<br /><br />";
if(mysql_num_rows($gc) <= 0){
echo "<b>You currently don't have any messages.</b>.";
}else{
echo "<table width=\"753\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\">";
echo "<tr><td width=\"20\" height=\"5\">Status<br></td><td width=\"100\" height=\"5\">Subject<br></td><td width=\"100\" height=\"5\">Sender<br></td><td width=\"125\" height=\"5\">Date Sent<br></td><td width=\"50\" height=\"5\">MSG ID</td></tr><tr><td width=\"20\" height=\"5\"></td><td width=\"100\" height=\"5\"></td><td width=\"100\" height=\"5\"></td><td width=\"130\" height=\"5\"></td><td width=\"20\" height=\"5\"></td></tr>";
while($m = mysql_fetch_array($gc)){
echo "<tr><td width=\"20\" bgcolor=\"#FFFFCC\">";
if($m['new']=="1"){
echo "<b><font color=\"red\">(Unread)</font></b>";
}else{
echo "<b><font color=\"green\">(Read)</font></b>";
}
echo "</td><td width=\"100\" bgcolor=\"#FFFFCC\"><a href=\"messages.php?msgid=".$m['id']."\">".$m['subject']."</a></td><td width=\"100\" bgcolor=\"#FFFFCC\"><a href=\"members.php?name=".$m['sender']."\">".$m['sender']."</a></td><td width=\"125\" bgcolor=\"#FFFFCC\">".$m['sent_date']."</td><td width=\"50\" bgcolor=\"#FFFFCC\">".$m['id']."</td></tr>";
}
}
echo "</table>";
echo "</td></tr></table></table>";
}
}else{
echo "<table border=0 width=749 cellspacing=0 cellpadding=0><tr><td width=6 rowspan=3> </td><td><fieldset><legend><b>Error!</b></legend>";
echo "Your not aloud to view this page, your not logged in yet!";
echo "<br><br><b><a href=\"register.php\">Not a member? Click here to Register!</a></b>";
echo "</fieldset></td></tr></table>";
}
include("end.php");
?>