This repository has been archived by the owner on Mar 17, 2022. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 7
/
user_edit_profile.php
executable file
·103 lines (87 loc) · 3.34 KB
/
user_edit_profile.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
<?php
/**
* Description of user_edit_profile.php
* version: 1.0
* package: Dracker - Track and Trace
* copyright: Copyright (C) 2013 Gareth Phillips. All rights reserved.
* license: GNU/GPL, see license.htm.
*
* This file is part of the Dracker project.
*
* Dracker is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, under version 3 of the License.
*
* Dracker is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with Dracker. If not, see <http://www.gnu.org/licenses/>.
*
* @author GPhillips
**/
include_once 'configs/DatabaseConnection.php';
$include_allowed = true;
session_start();
$sessionid= session_id();
$sessionid=sanitize($sessionid);
$connection = new DatabaseConnection();
$queryLoggedinDetail = $connection->executeQuery("SELECT uid FROM loggedin WHERE session = '$sessionid'");
while ($rowLoggedinID = mysql_fetch_array($queryLoggedinDetail)){
$userid=$rowLoggedinID['uid'];
$queryUserEmail = $connection->executeQuery("SELECT * FROM user_account WHERE id = '$userid'");
while ($rowUserEmail = mysql_fetch_array($queryUserEmail)){
$email=$rowUserEmail['email'];
$name=$rowUserEmail['name'];
$surname=$rowUserEmail['surname'];
}
}
function cleanInput($input) {
$search_input = array(
'@<script[^>]*?>.*?</script>@si', // Strip out javascript
'@<[\/\!]*?[^<>]*?>@si', // Strip out HTML tags
'@<style[^>]*?>.*?</style>@siU', // Strip style tags properly
'@<![\s\S]*?--[ \t\n\r]*>@' // Strip multi-line comments
);
$output = preg_replace($search_input, '', $input);
return $output;
}
function sanitize($input) {
if (is_array($input)) {
foreach($input as $var=>$val) {
$output[$var] = sanitize($val);
}
}
else {
if (get_magic_quotes_gpc()) {
$input = stripslashes($input);
}
$input = cleanInput($input);
$connection = new DatabaseConnection();
$output = mysql_real_escape_string($input);
}
return $output;
}
?>
<div class="modal-header">
<button type="button" class="close" data-dismiss="modal" aria-hidden="true">×</button>
<h5 id="edituserModalLabel">Update Your Profile </h5>
</div>
<div class="well">
<form method="POST" action="settings.php">
<label>Name
<input type="text" value="<? echo $name;?>" class="input-medium" autocomplete="off" id="upname" name="upname" required>
Surname
<input type="text" value="<? echo $surname;?>"class="input-medium" autocomplete="off" id="upsurname" name="upsurname" required></label>
</label>
<label>Email
<input type="text" value="<? echo $email;?>" class="input-large" autocomplete="off" id="upemail" name="upemail" required></label>
<br>
<div class="modal-footer">
<button class="btn-flat gray" data-dismiss="modal" aria-hidden="true">Cancel</button>
<button class="btn-flat primary" >Update</button>
</div>
</form>
</div>