Forum Moderators: coopster
<?php include($_SERVER['DOCUMENT_ROOT']."/includes/login.php"); ?>
<?php if(isset($_GET['p_id']) && !empty($_GET['p_id'])){
$SqlQuery = "SELECT * FROM `data` WHERE `id` = '".strip_tags(mysql_real_escape_string($_GET['p_id']))."' ";
$SqlSent = mysql_query($SqlQuery) or die(mysql_error());
while($result = mysql_fetch_array($SqlSent)){ ?>
<?php
$i=0;
while ($i < $num) {
$add=mysql_result($result,$i,"pri");
++$i;
}
$u_add=$_POST['add'];
?>
<p><form name="form" method="post">
<input type="text" name="pri" value="<?php echo $add; ?>" />
<input type="submit" name="submit" value="Submit" />
or <a href="/cp">Go back to Control Panel</a>
</form></p>
<?php
$id = $result['id'];
if(isset($_POST['pri'])) {
$a = mysql_query("UPDATE data SET pri = '$add' WHERE id = '$id'");
if($a) {
echo "<br />Price updated successfully! Click <a href='/cp/'>here</a> to go back to <a href='/cp/'>Control Panel</a>";
}else {
echo "<br />error";
}
}
?>
<?php }
}
else{
header("location: /cp/");
exit;
}
?>
$a = mysql_query("UPDATE data SET pri = '500' WHERE id = '$id'");