Advertisement
Guest User

Untitled

a guest
May 28th, 2018
111
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. <?php
  2. session_start();
  3. include("db.php");
  4. // Connessione al database
  5. $conn = mysqli_connect($db_host, $db_user, $db_password);
  6. mysqli_select_db($conn, $db_database);
  7.  
  8. mysqli_begin_transaction($conn);
  9. // Leggo i dati dall'updateinfo
  10. // evito injection
  11. $username=mysqli_escape_string($conn,$_POST["username"]);
  12. $password=mysqli_escape_string($conn,$_POST["password"]);
  13. $name=mysqli_escape_string($conn,$_POST["name"]);
  14. $surname=mysqli_escape_string($conn,$_POST["surname"]);
  15. $email=mysqli_escape_string($conn,$_POST["email"]);
  16. $birth=mysqli_escape_string($conn,$_POST["birth"]);
  17. // Cripta password
  18. $password = md5($password);
  19.  
  20. // controllo se l'username inserito รจ presente nel DB
  21. $query=mysqli_query($conn,"SELECT * FROM account where username ='".$username."'");
  22. $row=mysqli_fetch_array($query,MYSQLI_ASSOC);
  23.  
  24. if($row)
  25. {
  26. echo "<html>";
  27. echo "<body>";
  28. echo "Username gi&agrave esistente<br>";
  29. echo "<a href='Accountinfo.php'> Torna indietro </a><br>";
  30. echo "</body>";
  31. echo "</html>";
  32. }
  33. else
  34. {
  35. mysqli_query($conn,"UPDATE account SET password='".$password."',username='".$username."' WHERE user_id =".$_SESSION["user_id"]);
  36. mysqli_query($conn,"UPDATE users SET name='".$name."',surname='".$surname."',birth='".$birth."',email='".$email."' WHERE user_id=".$_SESSION["user_id"]);
  37.  
  38.  
  39. }
  40. mysqli_commit($conn);
  41.  
  42. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement