<?
$host = "localhost"; // Host name
$username = "ptanner_cmx"; // Mysql username
$password = "ORgANic1@3"; // Mysql password
$db_name = "ptanner_cmx"; // Database name
$tbl_name = "cart_customers"; // Table name
$tbl_name2 = "cart_invoice"; // Table name
// Connect to server and select databse.
include_once("classes/DB.class.php");
include_once("functions/mbstrings.php");
?>
<html>
<head>
<style type="text/css">
#search-box{
background-color: #f7f7f7;
border: 1px solid #cccccc;
}
#text1{
font-size: 8pt;
color: #000;
}
</style>
</head>
<body>
<table width="100%" cellpadding="0" cellspacing="0" border="0">
<tr><td class="nav"><a href="index.php?section=home">Home</a> > <a href="index.php?section=manage_blogs">Manage Blogs</a></td></tr>
<tr><td> </td></tr>
<tr><td id="text1">
<?php
if ($_POST['delete']){
$sql = "delete FROM cart_customers WHERE
prikey = '". $_POST['prikey'] . "'
AND billto_firstname = '". $_POST['billto_firstname'] . "'
AND billto_lastname = '". $_POST['billto_lastname'] . "'
AND username = '". $_POST['username'] . "'
AND password = '". $_POST['password'] . "'";
$GLOBALS["DB"]->execute($sql);
echo "Item Delete<br>";
}
$sql_query = "SELECT prikey,billto_firstname,billto_lastname,billto_phone,username,password FROM cart_customers";
if ($_GET['prikey'])
$sql_query .= " WHERE prikey = '" . $_GET['prikey']."'";
if ($_GET["billto_firstname"])
$sql_query .= " WHERE billto_firstname like '%". $_GET["billto_firstname"] . "%'";
if ($_GET["billto_lastname"])
$sql_query .= " WHERE billto_lastname like '%". $_GET["billto_lastname"] . "%'";
if ($_GET["billto_phone"])
$sql_query .= " WHERE billto_phone like '%". $_GET["billto_phone"] . "%'";
if ($_GET["username"])
$sql_query .= " WHERE username like '%". $_GET["username"] . "%'";
if ($_GET["password"])
$sql_query .= " WHERE password like '%". $_GET["password"] . "%'";
$result = $GLOBALS["DB"]->result($sql_query);
echo "
<table>
<tr>
<td class'text1'>OPTIONS</td>
<td>PRIKEY</td>
<td>FIRST NAME</td>
<td>LAST NAME</TD>
<td>PHONE</td>
<td>USERNAME</td>
<td>PASSWORD</td>
<td>ACTION</td>
</tr>";
echo "
<form method='get'>
<tr>
<td>
<select name=type>
<option value='0'>ALL</option>
<option value='prikey'>Prikey</option>
<option value='billto_firstname'>First Name</option>
<option value='billto_lastname'>Last Name</option>
<option value='billto_phone'>Phone</option>
<option value='username'>Username</option>
<option value='password'>Password</option>
</select>
</td>
<td><input type=text name='prikey'></td>
<td><input type=text name='billto_firstname'></td>
<td><input type=text name='billto_lastname'></td>
<td><input type=text name='billto_phone'></td>
<td><input type=text name='username'></td>
<td><input type=text name='password'></td>
</td>
<td> </td>
<td>
<input type=submit name=submit value=Filter></form>
</td>
</tr>
";
foreach($result as $res){
echo "
<tr>
<td></td>
<td class'text1'>".$res["prikey"] . "</td>
<td class'text1'>" . $res["billto_firstname"]. "</td>
<td class'text1'>" . $res["billto_lastname"]. "</td>
<td class'text1'>" . $res["billto_phone"]. "</td>
<td class'text1'>" . $res["username"] . "</td>
<td class'text1'>" . $res["password"]. "</td>
<td><form method=post>
<input type=hidden name=delete value=1>
<input type=hidden name=prikey value=\"" . $res["prikey"]. "\">
<input type=hidden name=billto_firstname value=\"" . $res["billto_firstname"]. "\">
<input type=hidden name=billto_lastname value=\"" . $res["billto_lastname"]. "\">
<input type=hidden name=billto_phone value=\"" . $res["billto_phone"]. "\">
<input type=hidden name=username value=\"" . $res["username"]. "\">
<input type=hidden name=password value=\"" . $res["password"]. "\">
<input type=submit name=submit value=\"Delete\">
</form></td>
</tr>
";
}//foreach
echo "</table>";
?>
</td></tr></table>
</body>
</html>