HEX
Server: Microsoft-IIS/8.5
System: Windows NT YDAWBH120 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
User: tentjecom_web (0)
PHP: 7.4.14
Disabled: NONE
Upload Files
File: D:/HostingSpaces/EUmans/dak-spouwmuurisolatie.be/wwwroot/kms/project_wijzigen.php
<?php
include("ckeditor/ckeditor.php");

$project_id = $_GET['project_id'];

$project_id = checkData($project_id);
	
if(!isset($_POST['verzenden'])){
	
	$q_nieuws = sprintf("SELECT kms_spouwmuur_projecten.naam, kms_spouwmuur_projecten.categorie, kms_spouwmuur_projecten.image_dir FROM kms_spouwmuur_projecten WHERE project_id='%s'", $project_id);
	$r_nieuws = mysql_query($q_nieuws);
	$rec_nieuws = mysql_fetch_array($r_nieuws);
	
	$naam = html_entity_decode($rec_nieuws['naam']);
	$categorie = html_entity_decode($rec_nieuws['categorie']);
	$image = $rec_nieuws['image_dir'];

}

if(isset($_POST['verzenden'])){
	$verzenden = true;
}
if(isset($_POST['naam'])){
	$naam = $_POST['naam'];
	$naam = trim($naam);
	$lengte_naam = strlen($naam);
	if(($lengte_naam > 1) && ($lengte_naam < 150)){
		$valid_naam = true;
		$te_lang_naam = false;
	}else{
		$valid_naam = false;
		if($lengte_naam != 0){
			$te_lang_naam = true;
		}
	}
}else{
	$valid_naam = false;
}
if(isset($_POST['categorie'])){
	$categorie = $_POST['categorie'];
}
if($verzenden && $valid_naam && !empty($_POST['categorie'])){
	
	$naam_test = checkData($_POST['naam']);
	$categorie_test = checkData($_POST['categorie']);
	$test_url = friendlyURL($naam_test);
	
	$q_cases = sprintf("SELECT kms_spouwmuur_projecten.url FROM kms_spouwmuur_projecten WHERE kms_spouwmuur_projecten.url='%s' AND kms_spouwmuur_projecten.categorie = '%s'", $test_url, $categorie_test);
	$r_cases = mysql_query($q_cases);
	$rec_cases = mysql_fetch_array($r_cases);
	
	$uitkomst = $rec_cases['url'];
	
	if($test_url == $uitkomst){
		$bestaat_niet = false;	
	}else{
		$bestaat_niet = true;		
	}	
	
	$q_cases2 = sprintf("SELECT kms_spouwmuur_projecten.url FROM kms_spouwmuur_projecten WHERE project_id='%s'", $project_id);
	$r_cases2= mysql_query($q_cases2);
	$rec_cases2 = mysql_fetch_array($r_cases2);
	$org_name = $rec_cases2['url'];
	
	if($test_url == $org_name){
		$bestaat_niet = true;
	}
}
//check if al bestaat

if($_FILES['image_file']['tmp_name']){
	
	$valid_file = false;
	$valid_type = false;
	
	$file_tegroot = false;
	$valid_file = true;
	$extensions = array("image/jpg", "image/jpeg", "image/pjpeg");
	
	if(in_array($_FILES['image_file']['type'], $extensions)) { 
	   $valid_type = true; 
	}else{	
		$valid_type = false;
	}

}else{
	$valid_file = true;
	$valid_type = true;
}

if($verzenden && $valid_naam && $bestaat_niet && !empty($categorie) && $valid_type ){

	$url = friendlyURL($naam);
		
	$q_artikel_id = sprintf("SELECT kms_spouwmuur_projecten.project_id, kms_spouwmuur_projecten.image_dir FROM kms_spouwmuur_projecten WHERE kms_spouwmuur_projecten.url='%s'", $url);
	$r_artikel_id = mysql_query($q_artikel_id);
	$rec_artikel_id = mysql_fetch_assoc($r_artikel_id);
	
	$root = $_SERVER['DOCUMENT_ROOT']."/";
	
	if($_FILES['image_file']['tmp_name']){
		
		$nieuweThumb = true;
		
		$dirname = $rec_artikel_id['image_dir'];
		
		unlink($root.'/project_images/'.$image_dir.'/thumb_groot.jpg');
		
		$extensions = array("image/jpg", "image/jpeg", "image/pjpeg");
		
		if(in_array($_FILES['image_file']['type'], $extensions)) 
		{ 
			if($_FILES['image_file']['type'] == "image/jpg"){
				$ext = ".jpg";
			}else if($_FILES['image_file']['type'] == "image/jpeg"){
				$ext = ".jpg"; 
			}else if($_FILES['image_file']['type'] == "image/pjpeg"){
				$ext = ".jpg";
			}

		   $picture = $_FILES['image_file']['tmp_name'];
		   
		   list($width, $height) = getimagesize($picture);
		   
		   $objResize = new RVJ_ImageResize($_FILES['image_file']['tmp_name'], $root . '/project_images/'. $dirname . '/thumb_groot.jpg', 'W', '500');	
		}
	}else{
		$nieuweThumb = false;
	}
	
	$naam = utf8_decode($naam);
	$naam = htmlentities($naam);
	$naam = checkData($naam);
	
	$categorie = checkData($categorie);
	
	$q_account = sprintf("UPDATE kms_spouwmuur_projecten SET naam = '%s', categorie = '%s', url = '%s' WHERE kms_spouwmuur_projecten.project_id='%s'", 
	$naam,
	$categorie,
	$url,
	$project_id);
	
	$r_account = mysql_query($q_account);
	
	
	if($r_account){	

		if($nieuweThumb){
			header ('HTTP/1.1 301 Moved Permanently');
  			header ('Location: /kms/index.php?p=project_thumb&url='.$url);
		}else{
			echo("Project succesvol gewijzigd!<br /><br />");
			echo("<a href=\"index.php?p=projectfoto_overzicht&amp;project_id=".$project_id."\" title=\"Foto's beheren\">Foto's van dit project beheren</a>");
			echo("<br /><br /><a href=\"index.php?p=project_overzicht\" title=\"Terug naar het overzicht\">Terug naar het overzicht</a>");
		}
	}else{
		echo("Er is iets fout gegaan.");
	}
	
}else{
?>

<h1>Project wijzigen</h1>
<p>Vul onderstaande gegevens in om het project te wijzigen.</p>
<span class="label">* = verplicht</span><br /><br />
<form enctype="multipart/form-data" action="<?php $_SERVER['PHP_SELF']; ?>" id="aanmelden" name="aanmelden" method="post">
    	    
	<div>   
        <label>Naam*</label>
		<input name="naam" type="text" value="<?php echo($naam); ?>" />
        <?php if(!$valid_naam && $verzenden){ echo("<span class=\"error\"> (foutieve invoer)</span>"); }?>
        <?php if(!$valid_naam && $verzenden && $te_lang_naam){ echo("<span class=\"error\"><br />(invoer te lang)</span>"); }?>
        <?php if($valid_naam && $verzenden && !$bestaat_niet){ echo("<span class=\"error\"><br />(de naam bestaat al)</span>"); }?><br />
        
        <label>Categorie:*</label>
        <select name="categorie" >
			<option value="spouwmuurisolatie" <?php if ($categorie == "spouwmuurisolatie") { echo("selected=\"selected\"");} ?>>Spouwmuurisolatie</option>
        </select>
        <?php if(empty($categorie) && $verzenden){ echo("<span class=\"error\"> (selecteer een categorie)</span>"); }?>
        
       <br /><br />
       
       	<label>Thumb wijzigen<br />(.jpg)</label>
     	<input class="file_input" type="file" name="image_file" />
       	
        <br />
		<?php if(!$valid_type && !$valid_file && $verzenden && !$file_tegroot){ print("<span class=\"error\"><br />(Selecteer een afbeelding)</span>"); }?>
        <?php if(!$valid_type && $valid_file && $verzenden && !$file_tegroot){ print("<span class=\"error\"><br />(Alleen jpg bestanden)</span>"); }?>
		<?php if($file_tegroot && $verzenden){ print("<span class=\"error\"><br />(Uw bestand is te groot. Max 1 MB)</span>"); }?><br />
        

     <br /><br />
        <input name="verzenden" type="submit" value="Wijzigen" class="submit" />
        <a class="submit_annuleren" href="index.php?p=project_overzicht" title="Annuleren">Annuleren</a>
	</div>
</form>

<?php
}
?>