Advertisement
Guest User

Untitled

a guest
May 1st, 2017
67
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.00 KB | None | 0 0
  1. <?php
  2. require ("./includes/userfunctions.php");
  3. $data = mysql_query("SELECT * FROM users WHERE `username`='" . $_SESSION['username'] . "'")
  4. or die(mysql_error());
  5. $info = mysql_fetch_array( $data ); // puts the "users" info into the $info array
  6.  
  7. if (isset ($_SESSION['username']) && $info['membertype'] == 'Channel Op') {
  8.  
  9. if ($_GET['user'] == '' | $_GET['user'] == NULL) {
  10. echo '
  11. <div id="biobox" style="width: 765px; padding: 5px;">
  12. <h2 style="margin-left: 5px;">5709 Admin Control Panel</h2>
  13.  
  14. <div id="bioboxcontent">
  15. <div class="personlist" style="width: 593px; margin: 0 auto; margin-bottom: 10px;">
  16. <p>Please Select A User To Edit.</p>
  17. <ul>
  18. ';
  19. ACPgetMember('username ASC');
  20. echo '
  21. </ul>
  22. </div>
  23. </div>
  24. </div>
  25. ';
  26. }
  27.  
  28. else {
  29. $escape_user = mysql_real_escape_string($_GET['user']); //lets sanitise the username to prevent mysql injection
  30. $data = mysql_query("SELECT * FROM users WHERE `userid`='" . $escape_user . "'")
  31. or die(mysql_error());
  32.  
  33.  
  34. $info = mysql_fetch_array( $data ); // puts the "users" info into the $info array
  35.  
  36. if ($info['banned'] == '1') {
  37. $bannedcheck = 'checked = "yes"';
  38. }
  39.  
  40. else {
  41. $bannedcheck = '';
  42. }
  43. echo '
  44. <div id="biobox" style="width: 765px; padding: 5px;">
  45. <p><a href="index.php?page=admincp">Admin CP</a> > <a href="index.php?page=admincp&user=' . $info['userid'] . '">' . $info['username'] . '</a></p>
  46. <h2 style="margin-left:5px;">Edit User ' . $info['username'] . '</h2>
  47. <div id="bioboxcontent" style="padding: 5px;">
  48. <form id="acpform" action="index.php?page=admincp&user=' . $info['userid'] . '" method="post">
  49. <p>Username: <br /><input type="text" name="username" value="' . $info['username'] . '" /></p>
  50. <p>Member Type: <br /><input type="text" name="membertype" value="' . $info['membertype'] . '" /></p>
  51. <p>Avatar URL: <br/><input type="text" name="avatarURL" value="' . $info['avatarURL'] . '" /></p>
  52. <p>E-Mail Address: <br /><input type="text" name="email" value="' . $info['email'] . '" /></p>
  53. <p>Website: <br/><input type="text" name="websiteurl" value="' . $info['websiteurl'] . '"/></p>
  54. <p>Password: <br/><input type="password" name="password" /></p>
  55. <p>Banned? <br /><input type="checkbox" name="banned" style="width: 40px;" ' . $bannedcheck . '/></p>
  56. <input style="width: 100px;" type="submit" value = "Submit" />
  57. <textarea style="float: right; margin-top: -429px;" type="text" name="biography">' . $info['biography'] . '</textarea>
  58. </form>
  59. </div>
  60. </div>';
  61.  
  62. $username = mysql_real_escape_string($_POST['username']);
  63. $membertype = mysql_real_escape_string($_POST['membertype']);
  64. $avatarURL = mysql_real_escape_string($_POST['avatarURL']);
  65. $email = mysql_real_escape_string($_POST['email']);
  66. $websiteurl = mysql_real_escape_string($_POST['websiteurl']);
  67. $bannedcheck = $_POST['banned'];
  68. $biography = mysql_real_escape_string($_POST['biography']);
  69.  
  70. if ($_POST['password'] == '' | $_POST['password'] == NULL){
  71. mysql_query("UPDATE users SET username='" . $username . "', membertype='" . $membertype . "', avatarURL='" . $avatarURL . "', email='" . $email . "', websiteurl='" . $websiteurl . "', banned='" . $bannedcheck . "', biography='" . $biography . "' WHERE username='" . $info['username'] . "'")
  72. or die(mysql_error());
  73. }
  74.  
  75. else{
  76. $password = $_POST['password'];
  77. mysql_query("UPDATE users SET username='" . $username . "', membertype='" . $membertype . "', avatarURL='" . $avatarURL . "', email='" . $email . "', websiteurl='" . $websiteurl . "', banned='" . $bannedcheck . "', biography='" . $biography . "' WHERE username='" . $info['username'] . "'")
  78. or die(mysql_error());
  79. }
  80.  
  81. }
  82.  
  83. }
  84.  
  85. else {
  86. echo '<p>You do not have the required permissions to access this page</p>';
  87. }
  88.  
  89. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement