Problem polega na tym, że jak zaloguje się na konto admina, wejdę do PA i zmienia hasło użytkownika
test i klikam ok to zostaje zalogowany na konto użytkownika
test z uprawnieniami admina
u_view.adm.php<?php
include('config.php');
function escape($data){
}
}
function view_user(){
$query="SELECT * FROM user";
echo'<table align="center" border="0"> <tr>
<td align="left" width="20">Np.</td>
<td width="100">Login</td>
<td width="100">Data rejstracji</td>
</tr>';
<td align=\"left\" width=\"20\">{$row['user_id']}</td>
<td><a href=\"mailto:{$row['email']}\">{$row['username']}</a></td>
<td>{$row['data_rejstacji']}</td>
<td width=\"100\" align=\"center\"><a href=\"u_view.php?cmd=edit&id={$row['user_id']}\">edytuj</a> :: <a href=\"u_view.php?cmd=del&id={$row['user_id']}\">usun</a></td>
</tr>";
}
}
function edit_form(){
GLOBAL $dbc, $username, $password, $email, $id, $PHP_SELF;
$query="SELECT * FROM user WHERE user_id='{$_GET['id']}'";
echo '<form method="post" action="'.$_SERVER['PHP_SELF'].'?cmd=update&id='.$_GET['id'].'"> <table align="center" border="0">
<tr>
<td align="right">username:</td>
<td><input type="text" name="username" value="'.$row['username'].'" size="30">
</td>
</tr>
<tr>
<td align="right">email:</td>
<td><input type="text" name="email" value="'.$row['email'].'" size="30">
</td>
</tr>
<tr>
<td align="right">password:</td>
<td><input type="password" name="password" "size="30">
</td>
</tr>
<tr>
<td align="right"> </td>
<td><input style="font-weight: bold;" type="submit" name="submit" value="Zmien">
<input type="reset" name="Reset" value="wyczyść">
</td></tr>
</table>
</form>';
}
function update(){
GLOBAL $dbc, $username, $email, $password, $id;
$username = escape($_POST['username']);
$email = escape($_POST['email']);
if (isset($_POST['password'])){ $query = "UPDATE user SET username='$username', email='$email', haslo=PASSWORD('{$_POST['password']}') WHERE user_id='{$_GET['id']}'";
}else{
$query = "UPDATE user SET username='$username', email='$email'WHERE user_id='{$_GET['id']}'";
}
echo 'Dane zostały zmienione<Br />'; echo '<a href="admin.php?cmd=ok">Strona głowna</a>'; }
?>