<?php
include("headers.php");
include("menu.php");
session_start();
$passwordthatmustbesecret = "*****";
$hostthatmustbesecret = "localhost";
$usernamethatmustbesecret = "*****";
$databasethatmustbesecret = "*****_wwe";
$data->login = ($_SESSION['usr']);
mysql_connect($hostthatmustbesecret,$usernamethatmustbesecret,$passwordthatmustbesecret);
mysql_select_db($databasethatmustbesecret);
print " <tr><td class=\"mainTxt\"><a href=\"profile.php?x=$data->login\">Look at your profile</a></td></tr>\n";
?>
<?php
if ($_SERVER['REQUEST_METHOD'] == 'POST') {
$sql = "UPDATE tz_members SET url = '";
$sql .= urlencode(mysql_real_escape_string($_POST['url'])) . "',";
$sql .= "info = '" . mysql_real_escape_string($_POST['info']) . "',";
$sql .= "laand = '" . htmlspecialchars(mysql_real_escape_string($_POST['laand'])) . "',";
$sql .= "age = '" . htmlspecialchars(mysql_real_escape_string($_POST['age'])) . "' ";
$sql .= "WHERE usr = '" . $_SESSION['usr'] . "'";
$result = mysql_query($sql);
if ($result) {
if (mysql_affected_rows() == 1)
print '<tr><td class="mainTxt">You successfully updated your profile!</td></tr>'. "\n";
else
print '<tr><td class="mainTxt">Update failed; User doesn\'t excist!</td></tr>'. "\n";
}
else
print mysql_error() . '<br>' . $sql;
}
?>
<tr><td class="mainTxt">
<form method="post"><table align="center">
<tr><td width=100>Country:</td> <td><input type="text" name="$sql->laand"></td></tr>
<tr><td width=100>Age:</td> <td><input type="text" name="$sql->age"></td></tr>
<tr><td width=100>Avatar:</td> <td><input type="text" name="$sql->url"></td></tr>
<tr><td width=100 valign="top">Profile content:<br><br>
<td><textarea name="$sql->info" cols=30 rows=10></textarea></td></tr>
<tr><td></td> <td align="right"><input type="submit" name="submit" value="Update"></td></tr>
</table></form></td></tr></table>
Deze code heb ik nu. Laatst gewijzigd na hulp van "Ger van Steenderen".
2.252 views