Guest User

Untitled

a guest
Jan 14th, 2019
127
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.38 KB | None | 0 0
  1. Updating Multiple Fileds with logged in user and SHA1 Password
  2. $query = "UPDATE user SET username='$_POST[username]',
  3. nicename='$_POST[nicename]',
  4. email='$_POST[email]',
  5. password=(SHA1)'$_POST[password]',
  6. position='$_POST[position]',
  7. race='$_POST[race]',
  8. type='$_POST[type]' WHERE username=$_SESSION[admin_login]";
  9.  
  10. $nicename = mysqli_real_escape_string($connect, $_POST['nicename']);
  11.  
  12. $hashed_pass = sha1($_POST['password']);
  13.  
  14. //Query goes here
  15.  
  16. WHERE username='".$_SESSION[admin_login]."'";
  17.  
  18. $dbh = new PDO("mysql:host=$host;dbname=$dbname", $user, $pass);
  19.  
  20. $password = sha1($_POST[password]);
  21.  
  22. $stmt = $dbh->prepare("UPDATE user SET username = :username, nicename = :nicename, email = :email, password = :password, position = :position, race = :race, type = :type WHERE = :username");
  23. $stmt->bindParam(':username', $_POST['username']);
  24. $stmt->bindParam(':nicename', $_POST['nicename']);
  25. $stmt->bindParam(':email', $_POST['email']);
  26. $stmt->bindParam(':password', $password);
  27. $stmt->bindParam(':position', $_POST['position']);
  28. $stmt->bindParam(':race', $_POST['race']);
  29. $stmt->bindParam(':type', $_POST['type']);
  30. $stmt->bindParam(':username', $_SESSION['admin_login']);
  31.  
  32. $stmt->execute();
  33.  
  34. <?php
  35. $link = mysqli_connect('localhost', 'my_user', 'my_password', 'my_db');
  36.  
  37. $username = mysqli_real_escape_string($link, (string) $_POST['username']);
  38. $nicename = mysqli_real_escape_string($link, (string) $_POST['nicename']);
  39. $email = mysqli_real_escape_string($link, (string) $_POST['email']);
  40. $email = preg_replace( '/^[_a-zA-Z0-9-]+(.[_a-zA-Z0-9-]+)*@[a-zA-Z0-9-]+(.[a-zA-Z0-9-]+)*.(([0-9]{1,3})|([a-zA-Z]{2,3})|(aero|coop|info|museum|name))$/', $email );
  41. $password = sha1((string) $_POST['password']);
  42. $position = mysqli_real_escape_string($link, (string) $_POST['position']);
  43. $race = mysqli_real_escape_string($link, (string) $_POST['race']);
  44. $type = mysqli_real_escape_string($link, (string) $_POST['type']);
  45. $admin = $_SESSION['admin_login'];
  46.  
  47. $query = "UPDATE `user`
  48. SET `username`='$username',
  49. `nicename`='$nicename',
  50. `email`='$email',
  51. `password`='$password',
  52. `position`='$position',
  53. `race`='$race',
  54. `type`='$type'
  55. WHERE `username`='$admin'";
  56.  
  57. mysqli_query($link, $query);
  58. mysqli_close($link);
Add Comment
Please, Sign In to add comment