Current Path : /home/da040400/www_root/adm/
Upload File :
Current File : /home/da040400/www_root/adm/zmena_hesla.php

<?php
	//Start session
	session_start();
	
	//Include database connection details
	require_once('config.php');
	
	//Array to store validation errors
	$errmsg_arr = array();
	
	//Validation error flag
	$errflag = false;
	
	//Connect to mysql server
	$link = mysql_connect(DB_HOST, DB_USER, DB_PASSWORD);
	if(!$link) {
		die('Failed to connect to server: ' . mysql_error());
	}
	
	//Select database
	$db = mysql_select_db(DB_DATABASE);
	if(!$db) {
		die("Unable to select database");
	}
	
	//Function to sanitize values received from the form. Prevents SQL injection
	function clean($str) {
		$str = @trim($str);
		if(get_magic_quotes_gpc()) {
			$str = stripslashes($str);
		}
		return mysql_real_escape_string($str);
	}
	
	//Sanitize the POST values
	
	$password = clean($_POST['passwd']);
	$cpassword = clean($_POST['cpasswd']);
	$member_id = $_POST["member_id"];
	$login = clean($_POST['login']);
	//Input Validations
	
	if($password == '') {
		$errmsg_arr[] = 'heslo | ';
		$errflag = true;
	}
	if($cpassword == '') {
		$errmsg_arr[] = 'potvrdenie hesla | ';
		$errflag = true;
	}
	if( strcmp($password, $cpassword) != 0 ) {
		$errmsg_arr[] = 'heslo sa nezhoduje';
		$errflag = true;
	}
	
	if($password != '') {
		$qry2 = "SELECT * FROM members WHERE passwd='".md5($password)."'";
		$result2 = mysql_query($qry2);
		if($result2) {
			if(mysql_num_rows($result2) > 0) {
				$errmsg_arr[] = 'Heslo už je v databáze<br>Skús znovu';
				$errflag = true;
			}
			@mysql_free_result($result);
		}
		else {
			die("Query failed");
		}
	}
	
	//If there are input validations, redirect back to the registration form
	if($errflag) {
		$_SESSION['ERRMSG_ARR'] = $errmsg_arr;
		session_write_close();
		header("location: heslo.php");
		exit();
	}

	//Create INSERT query
	
  #$vysledok = MySQL_query("UPDATE members SET passwd = '".md5($passwd)."' WHERE member_id = '$member_id' LIMIT 1");
  #$qry = "INSERT INTO members(firstname, lastname, email, login, passwd) VALUES('$fname','$lname','$email', '$login','".md5($_POST['password'])."')";
  #$qry = "UPDATE members SET passwd = '".md5($_POST['password'])."' WHERE member_id = '$member_id'";
  $qry = "UPDATE members SET passwd = '".md5($password)."' WHERE member_id = '$member_id'";
  $result = @mysql_query($qry);
	
	//Check whether the query was successful or not
	if($result) {
		header("location: heslo_zmenene.php");
		exit();
	}else {
		die("Query failed");
	}
	
	
?>

DR.KR LITE SHELL COPYRIGHT 2016