summaryrefslogtreecommitdiff
path: root/www-ssl/inc/funktion_db.php
blob: 06decc479285a6c87728bbd36f8a15bf58a6f711 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
<?PHP

if( !function_exists("db_query"))
{
	function Ausgabe_Daten($SQL)
	{
		global $con;	
	
	
		$Erg = mysql_query($SQL, $con);
		echo mysql_error($con);
		
		$Zeilen  = mysql_num_rows($Erg);
		$Anzahl_Felder = mysql_num_fields($Erg);
		
		$Diff  = "<table border=1>";
		$Diff .= "<tr>";
		for ($m = 0 ; $m < $Anzahl_Felder ; $m++)
			$Diff .= "<th>". mysql_field_name($Erg, $m). "</th>";
		$Diff .= "</tr>";
		for ($n = 0 ; $n < $Zeilen ; $n++) 
		{
			$Diff .= "<tr>";
		        for ($m = 0 ; $m < $Anzahl_Felder ; $m++)
  	  			$Diff .= "<td>".mysql_result($Erg, $n, $m). "</td>";
        		$Diff .= "</tr>";
		}
		$Diff .= "</table>";
		return $Diff;
	}

	function db_query( $SQL, $comment)
	{
		global $con;	
		
		//commed anlyse udn daten sicherung
		$Diff = "";
		if( strpos( "#$SQL", "UPDATE") > 0)
		{
			//Tabellen name ermitteln
			$Table_Start = strpos( $SQL, "`");
			$Table_End   = strpos( $SQL, "`", $Table_Start+1);
			$Table = substr( $SQL, $Table_Start, ($Table_End-$Table_Start+1));
	
			//WHERE ermitteln
			$Where_Start = strpos( $SQL, "WHERE");
			$Where = substr( $SQL, $Where_Start);
			
			// sicherheitspr�fung !!!!
			if( $Where_Start == 0)	$Where = ";"; 

			//Daten auslesen
			$Diff .= Ausgabe_Daten( "SELECT * FROM $Table $Where");

			//execute command
			$querry_erg = mysql_query($SQL, $con);
			
			//Daten auslesen
			$Diff .= Ausgabe_Daten( "SELECT * FROM $Table $Where");
		}
		elseif( strpos( "#$SQL", "DELETE") > 0)
		{
			$TableWhere = substr( $SQL, 6);
			
			//Daten auslesen
			$Diff .= Ausgabe_Daten( "SELECT * $TableWhere");

			//execute command
			$querry_erg = mysql_query($SQL, $con);
		}
		elseif( strpos( "#$SQL", "INSERT") > 0)
		{
			echo "##### LOG: INSERT #####";
		}
		else
		{
			//execute command
			$querry_erg = mysql_query($SQL, $con);
		}

		//abschneiden wenn zu lang
		if( strlen( $Diff) > 5120) 	$Diff = "too mutch (len ". strlen( $Diff). ")";

		//LOG commands in DB
		$SQL_SEC =	"INSERT INTO `ChangeLog` ( `UID` , `SQLCommad` , `Commend` ) ".
				" VALUES ( ".
					"'". $_SESSION['UID']. "', ".
					"'SQL:<br>". htmlentities( $SQL, ENT_QUOTES). "<br><br>".
					 "Diff:<br>$Diff', ".
					"'". htmlentities( $comment, ENT_QUOTES). "' );";
		$erg = mysql_query($SQL_SEC, $con);
echo "##$erg";
		echo mysql_error($con);
echo "##";
		return $querry_erg;
	}//function db_query(
}

?>