Pref Edit Save.php:
<?
session_start();
// connect to database and pull up info
include "../config.php";
$user123=$_POST['Username'];
$db = mysql_connect($db_host, $db_user, $db_pass);
mysql_select_db ($db_name) or die ("Cannot connect to database");
//Get the data
$query = "SELECT id, level, username, password FROM users WHERE username='$user123' AND level='1'";
$result = mysql_query($query);
/* Here we fetch the result as an array */
while($r=mysql_fetch_array($result))
{
/* This bit sets our data from each row as variables, to make it easier to display */
$id=$r["id"];
$_level=$r["level"];
$_Username=$r["username"];
$_Password=$r["password"];
// If the form was submitted
if ($_POST['Submitted'] == "True") {
// If the username and password match up, then continue...
if ($_POST['Username'] == $_Username && $_POST['Password'] == $_Password && $_level == 1) {
// Username and password matched, set them as logged in and set the
// Username to a session variable.
$_SESSION['Logged_In'] = "True-Admin";
$_SESSION['Level'] = "1";
$_SESSION['Username'] = $_Username;
}
}
}
mysql_close($db);
// If they are NOT logged in then show the form to login...
if ($_SESSION['Logged_In'] != "True-Admin") {
?>
<?
include "style.php";
?>
<div class="boxxy"><br><br><form method="post" action="<?=$_SERVER['PHP_SELF'];?>">
<table cellpadding="0" cellspacing="0" border="0" align="center"><tr><td style="border-left: 1px solid gray; border-top: 1px solid gray; border-bottom: 1px solid gray;">Username:</td><td><input type="text" name="Username" style="border: 1px solid gray;"></td></tr><tr><td height="2"></td></tr><tr><td style="border-left: 1px solid gray; border-top: 1px solid gray; border-bottom: 1px solid gray;">Password:</td><td><input type="password" name="Password" style="border: 1px solid gray;"></td></tr><tr><td height="2"></td></tr><tr><td colspan="2" align="right"><input type="submit" style="border: 1px solid gray; font-family: verdana; font-size: 11px; background-color: white;" name="Submit" value="Submit"></td></tr><tr><td height="2"></td></tr><tr><td colspan="2" align="right"><a href="../fpass.php">Forget your Password?</a></td></tr></table> <input type="hidden" name="Submitted" value="True"></form>
</div>
<div class="boxtext" align="center"> <b>aWebBB Admin Login</b> </div>
<?
}
else
{
include "header.php";
include "../config.php";
$db = mysql_connect($db_host, $db_user, $db_pass);
mysql_select_db ($db_name) or die ("Cannot connect to database");
$query = "UPDATE prefs SET sitename='$_POST[sitename]', forumname='$_POST[forumname]', sitetitle='$_POST[sitetitle]', menulink='$_POST[menulink]', normallink='$_POST[normallink]', defimage='$_POST[otherav]', defsig='$_POST[defsig]', backcolor='$_POST[backcolor]', msitecolor='$_POST[msitecolor]', siteurl='$_POST[siteurl]', headimage='$_POST[headimage]', hiwidth='$_POST[hiwidth]', hiheight='$_POST[hiheight]', forumcolor='$_POST[forumcolor]', normaltext='$_POST[normaltext]', copyright='$_POST[copyright]', email='$_POST[email]'";
$result = mysql_query($query);
echo "Site Updated";
echo "<META HTTP-EQUIV=\"refresh\" content=\"1; URL=index.php\">";
mysql_close($db);
include "footer.php";
// If they want to logout then
if ($_GET['mode'] == "logout") {
// Start the session
session_start();
// Put all the session variables into an array
$_SESSION = array();
// and finally remove all the session variables
session_destroy();
// Redirect to show results..
echo "<META HTTP-EQUIV=\"refresh\" content=\"0; URL=" . $_SERVER['PHP_SELF'] . "\">";
}
}
?>
Other Discussion Boards Scripts: