1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
|
<?
// Laaser Shop System
// Copyright: Juergen Laaser, 2002-2007
// Bearbeitet von Nanni (M. Anderl)
// Includes
include ("../config.php");
// Variablen Deklaration
if (!isset($_POST['kategorie'])) $_POST['kategorie'] = "";
if (!isset($_POST['name_k'])) $_POST['name_k'] = "";
if (!isset($_POST['main_name'])) $_POST['main_name'] = "";
if (!isset($_POST['sort'])) $_POST['sort'] = "";
if (!isset($_POST['start'])) $_POST['start'] = "";
if (!isset($_POST['neu_kategorie'])) $_POST['neu_kategorie'] = "";
if (!isset($_POST['neu_artikelnummer'])) $_POST['neu_artikelnummer'] = "";
if (!isset($_POST['neu_name'])) $_POST['neu_name'] = "";
if (!isset($_POST['neu_beschreibung'])) $_POST['neu_beschreibung'] = "";
if (!isset($_POST['neu_preis'])) $_POST['neu_preis'] = "";
if (!isset($_POST['neu_variante1'])) $_POST['neu_variante1'] = "";
if (!isset($_POST['neu_variante2'])) $_POST['neu_variante2'] = "";
if (!isset($_POST['neu_status'])) $_POST['neu_status'] = "";
if (!isset($_POST['bild'])) $_POST['bild'] = "";
if (!isset($_POST['copyright'])) $_POST['copyright'] = "";
if (!isset($_POST['id'])) $_POST['id'] = "";
$post_vars = array();
$post_vars['neu_kategorie'] = htmlentities($_POST['neu_kategorie'],ENT_QUOTES,'utf-8');
$post_vars['neu_artikelnummer'] = htmlentities($_POST['neu_artikelnummer'],ENT_QUOTES,'utf-8');
$post_vars['neu_name'] = htmlentities($_POST['neu_name'],ENT_QUOTES,'utf-8');
$post_vars['neu_beschreibung'] = htmlentities($_POST['neu_beschreibung'],ENT_QUOTES,'utf-8');
$post_vars['neu_preis'] = htmlentities($_POST['neu_preis'],ENT_QUOTES,'utf-8');
$post_vars['neu_variante1'] = htmlentities($_POST['neu_variante1'],ENT_QUOTES,'utf-8');
$post_vars['neu_variante2'] = htmlentities($_POST['neu_variante2'],ENT_QUOTES,'utf-8');
$post_vars['neu_status'] = htmlentities($_POST['neu_status'],ENT_QUOTES,'utf-8');
$post_vars['bild'] = htmlentities($_POST['bild'],ENT_QUOTES,'utf-8');
$post_vars['copyright'] = $_POST['copyright'];
$post_vars['id'] = htmlentities($_POST['id'],ENT_QUOTES,'utf-8');
$post_vars['kategorie'] = htmlentities($_POST['kategorie'],ENT_QUOTES,'utf-8');
$post_vars['name_k'] = htmlentities($_POST['name_k'],ENT_QUOTES,'utf-8');
$post_vars['main_name'] = htmlentities($_POST['main_name'],ENT_QUOTES,'utf-8');
$post_vars['sort'] = htmlentities($_POST['sort'],ENT_QUOTES,'utf-8');
$post_vars['start'] = htmlentities($_POST['start'],ENT_QUOTES,'utf-8');
// Programm-Code
if (!$post_vars['neu_artikelnummer']): $action = "error";
elseif (!$post_vars['neu_name']): $action = "error";
elseif (!$post_vars['neu_beschreibung']): $action = "error";
elseif (!$post_vars['neu_preis']): $action = "error";
elseif (!$post_vars['neu_copyright']): $action = "error";
else: $action = "erfolg";
endif;
$conn_id = mysql_connect($HOST,$ID,$PW);
mysql_select_db($DB,$conn_id);
if ($action == "erfolg") {
if ($post_vars['bild'] == "ok" AND !is_uploaded_file($HTTP_POST_FILES['neu_bild']['tmp_name']))
{
mysql_query("update ".$PREFIX."_Artikel set kategorie ='{$post_vars['neu_kategorie']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set artikelnummer ='{$post_vars['neu_artikelnummer']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set name ='{$post_vars['neu_name']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set beschreibung ='{$post_vars['neu_beschreibung']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set preis ='{$post_vars['neu_preis']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set copyright ='{$post_vars['neu_copyright']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante1 ='{$post_vars['neu_variante1']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante2 ='{$post_vars['neu_variante2']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set status ='{$post_vars['neu_status']}' where id = '{$post_vars['id']}'");
}
if ($post_vars['bild'] != "ok" AND !is_uploaded_file($HTTP_POST_FILES['neu_bild']['tmp_name']))
{
mysql_query("update ".$PREFIX."_Artikel set kategorie ='{$post_vars['neu_kategorie']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set artikelnummer ='{$post_vars['neu_artikelnummer']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set name ='{$post_vars['neu_name']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set beschreibung ='{$post_vars['neu_beschreibung']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set preis ='{$post_vars['neu_preis']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set copyright ='{$post_vars['neu_copyright']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante1 ='{$post_vars['neu_variante1']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante2 ='{$post_vars['neu_variante2']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set status ='{$post_vars['neu_status']}' where id = '{$post_vars['id']}'");
}
if ($post_vars['bild'] == "ok" AND is_uploaded_file($HTTP_POST_FILES['neu_bild']['tmp_name']))
{
mysql_query("update ".$PREFIX."_Artikel set kategorie ='{$post_vars['neu_kategorie']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set artikelnummer ='{$post_vars['neu_artikelnummer']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set name ='{$post_vars['neu_name']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set beschreibung ='{$post_vars['neu_beschreibung']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set preis ='{$post_vars['neu_preis']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set copyright ='{$post_vars['neu_copyright']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante1 ='{$post_vars['neu_variante1']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante2 ='{$post_vars['neu_variante2']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set status ='{$post_vars['neu_status']}' where id = '{$post_vars['id']}'");
$fotoname = "{$post_vars['id']}.jpg";
if ($FTP == "1")
{
$conn_ftp = ftp_connect($HOST1);
ftp_login($conn_ftp,$ID1,$PW1);
ftp_chdir($conn_ftp,$PFAD1);
@ftp_delete($conn_ftp,$fotoname);
$mode = FTP_BINARY;
$file = fopen($HTTP_POST_FILES['neu_bild']['tmp_name'],"r");
@ftp_fput($conn_ftp,$fotoname,$file,$mode);
fclose($file);
}
else
{
unlink("../images/artikel/$fotoname");
move_uploaded_file(($HTTP_POST_FILES['neu_bild']['tmp_name']),"../images/artikel/$fotoname");
chmod ("../images/artikel/$fotoname", 0777);
}
}
if ($post_vars['bild']!= "ok" AND is_uploaded_file($HTTP_POST_FILES['neu_bild']['tmp_name']))
{
$bild = "ok";
mysql_query("update ".$PREFIX."_Artikel set kategorie ='{$post_vars['neu_kategorie']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set artikelnummer ='{$post_vars['neu_artikelnummer']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set name ='{$post_vars['neu_name']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set beschreibung ='{$post_vars['neu_beschreibung']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set preis ='{$post_vars['neu_preis']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set copyright ='{$post_vars['neu_copyright']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante1 ='{$post_vars['neu_variante1']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set variante2 ='{$post_vars['neu_variante2']}' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set bild ='$bild' where id = '{$post_vars['id']}'");
mysql_query("update ".$PREFIX."_Artikel set status ='{$post_vars['neu_status']}' where id = '{$post_vars['id']}'");
$fotoname = "{$post_vars['id']}.jpg";
if ($FTP == "1")
{
$conn_ftp = ftp_connect($HOST1);
@ftp_login($conn_ftp,$ID1,$PW1);
@ftp_chdir($conn_ftp,$PFAD1);
$mode = FTP_BINARY;
$file = fopen($HTTP_POST_FILES['neu_bild']['tmp_name'],"r");
@ftp_fput($conn_ftp,$fotoname,$file,$mode);
fclose($file);
}
else
{
move_uploaded_file(($HTTP_POST_FILES['neu_bild']['tmp_name']),"../images/artikel/$fotoname");
chmod ("../images/artikel/$fotoname", 0777);
}
}
mysql_close($conn_id);
header("Location: pro_show.php?kategorie={$post_vars['kategorie']}&id={$post_vars['id']}&action=$action&name_k={$post_vars['name_k']}&main_name={$post_vars['main_name']}&start={$post_vars['start']}&sort={$post_vars['sort']}");
}
else header("Location: pro_edit.php?kategorie={$post_vars['kategorie']}&id={$post_vars['id']}&action=$action&name_k={$post_vars['name_k']}&main_name={$post_vars['main_name']}&start={$post_vars['start']}&sort={$post_vars['sort']}");
?> |