Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- if (!function_exists("GetSQLValueString")) {
- function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "")
- {
- if (PHP_VERSION < 6) {
- $theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;
- }
- $theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);
- switch ($theType) {
- case "text":
- $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
- break;
- case "long":
- case "int":
- $theValue = ($theValue != "") ? intval($theValue) : "NULL";
- break;
- case "double":
- $theValue = ($theValue != "") ? doubleval($theValue) : "NULL";
- break;
- case "date":
- $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
- break;
- case "defined":
- $theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
- break;
- }
- return $theValue;
- }
- }
- $editFormAction = $_SERVER['PHP_SELF'];
- if (isset($_SERVER['QUERY_STRING'])) {
- $editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
- }
- if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "new_recipe")) {
- $insertSQL = sprintf("INSERT INTO recipes (reci_id, reci_name, reci_post_author, reci_post_datetime, reci_update_author, reci_update_datetime, reci_status, reci_difficulty, reci_serving, reci_cooktime_hours, reci_cooktime_mins, reci_preptime_hours, reci_preptime_mins, reci_cooltime_hours, reci_cooltime_mins, reci_category, reci_ingredients, reci_instructions, `reci_img_1`, `reci_img_2`, `reci_img_3`, `reci_img_4`, `reci_img_5`, `reci_img_6`, `reci_img_7`, `reci_img_8`, `reci_img_9`, `reci_img_10`) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s)",
- GetSQLValueString($_POST['reci_id'], "int"),
- GetSQLValueString($_POST['reci_name'], "text"),
- GetSQLValueString($_POST['reci_post_author'], "text"),
- GetSQLValueString($_POST['reci_post_datetime'], "text"),
- GetSQLValueString($_POST['reci_update_author'], "text"),
- GetSQLValueString($_POST['reci_update_datetime'], "text"),
- GetSQLValueString($_POST['reci_status'], "int"),
- GetSQLValueString($_POST['reci_difficulty'], "text"),
- GetSQLValueString($_POST['reci_serving'], "text"),
- GetSQLValueString($_POST['reci_cooktime_hours'], "text"),
- GetSQLValueString($_POST['reci_cooktime_mins'], "text"),
- GetSQLValueString($_POST['reci_preptime_hours'], "text"),
- GetSQLValueString($_POST['reci_preptime_mins'], "text"),
- GetSQLValueString($_POST['reci_cooltime_hours'], "text"),
- GetSQLValueString($_POST['reci_cooltime_mins'], "text"),
- GetSQLValueString($_POST['reci_category'], "text"),
- GetSQLValueString($_POST['reci_ingredients'], "text"),
- GetSQLValueString($_POST['reci_instructions'], "text"),
- GetSQLValueString($uploaded_image_names[0], "text"),
- GetSQLValueString($uploaded_image_names[1], "text"),
- GetSQLValueString($uploaded_image_names[2], "text"),
- GetSQLValueString($uploaded_image_names[3], "text"),
- GetSQLValueString($uploaded_image_names[4], "text"),
- GetSQLValueString($uploaded_image_names[5], "text"),
- GetSQLValueString($uploaded_image_names[6], "text"),
- GetSQLValueString($uploaded_image_names[7], "text"),
- GetSQLValueString($uploaded_image_names[8], "text"),
- GetSQLValueString($uploaded_image_names[9], "text"));
- mysql_select_db($database_planetcu_db6380, $planetcu_db6380);
- $Result1 = mysql_query($insertSQL, $planetcu_db6380) or die(mysql_error());
- $insertGoTo = "../../menu.php";
- if (isset($_SERVER['QUERY_STRING'])) {
- $insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
- $insertGoTo .= $_SERVER['QUERY_STRING'];
- }
- header(sprintf("Location: %s", $insertGoTo));
- }
- //........ je vous épargne le reste du code, ce sont des query pour remplire les stats.//
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement