Re: problem, Please help
| From: | Ben Schmidt | Date: | Sun, 20 Mar 2011 22:10:32 +0000 |
| Subject: | Re: problem, Please help | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-10666@lists.php.net to get a copy of this message | ||
Hi, Monika,
If you are doing a course, don't you have instructors who you are paying to help you learn? And fellow students who are tackling the same or similar problems? Why not ask them? I think that would make more sense than asking us.
If you do want to ask this community, though, the correct list is the "General user list", not this webmaster list. See here:
http://www.php.net/mailing-lists.php
I have had a quick look at your code and can't see any very obvious reason it wouldn't be working. However, you could be being bitten by a browser cache displaying old data, inappropriate data being submitted (e.g. if you do not submit a name, $errors will not be empty so no update will be attempted) or a database error you don't know about because you haven't checked for one, and perhaps error reporting isn't set to display it, or other things. Also, your code is insecure because you have not escaped the data the user enters before putting it in your SQL query string.
If you have further questions about any of this, you'd better take them to the general users list and see if someone there can help you. (Or talk to your instructors and fellow students!)
Good luck with your project.
Ben.
On 21/03/11 6:57 AM, Monika Cieluch wrote:
Hi I've just started PHP and i have a problem which i can't solve. Please can you help me find problem. I'm a student and this program is part of my project. I've got database with products. This part of the program is about updating product with new image. Image is uploaded but when I've change other details nothing have happened. Can you please help me find mistake. Monika Cieluch prodct is displayed in form <form enctype="multipart/form-data" action=\edit_product.php?pid={$row['product_id']}" method="POST"> part of code (update only): //UPDATE PRODUCT if (isset($_POST['submitted'])) {$errors=array(); $pid=(int)$_GET['pid']; //check for product name if(!empty($_POST['p_name'])){ $up_name=trim($_POST['p_name']); }else { $errors[]='Please enter the product name'; }//-----check for image ------------------------------------------------------------------------------ if(is_uploaded_file($_FILES['image']['tmp_name'])){ require ('Function/connection.php'); //set variable($pi) for product image$pi=$_FILES['image']['name']; $temp_pi=md5($_FILES['image']['name']);//check if photo was uploaded previously$sql="select photo_id from product where product_id='".$pid."'"; $result=mysql_query($sql,$dbc); while ($row=mysql_fetch_array($result)){//set image name to the image name which is existing, so i can be overwrite$pi=$row['photo_id']; $temp_pi=$pi; }//uploadpath$temp='upload_img/'.$temp_pi;//move fileif(move_uploaded_file($_FILES['image']['tmp_name'],$temp)){ echo("<p><br />The Image (<b><font color=\"red\">"..$_FILES['image']['name']. "</b></font>) Has Been Uploaded Successfully!<br />");$temp_pi=$_FILES['image']['name']; $query="update product set photo_id='".$temp_pi."' whereproduct_id='".$pid."'";$stmt = mysqli_prepare($dbc,$query); mysqli_stmt_bind_param($stmt,'s',$pi); mysqli_stmt_execute($stmt);if(mysqli_stmt_affected_rows($stmt)==1){ echo "<p> Picture updated</p>"; $id=$pid; rename($temp, "upload_img/$id");}else{ //echo "<p> Error try again</p> "; } mysqli_stmt_close($stmt);}else{//error when moving echo 'The file coulnt be moved'; $temp=$_FILES['image']['tmp_name']; } }//-------------------end image--------------------------------------------------------------------//check for price if(!empty($_POST['p_price'])){ $up_price=trim($_POST['p_price']); }else { $errors[]='Please enter the product price'; } //check for p_code, p_colour,p_width, p_heigh, p_description if emptyset to NULL if (empty($errors)) {$up_code=(!empty($_POST['p_code'])) ? trim($_POST['p_code']) : null; $up_colour=(!empty($_POST['p_colour'])) ? trim($_POST['p_colour']) :null;$up_width=(!empty($_POST['p_width'])) ? trim($_POST['p_width']) : null; $up_high=(!empty($_POST['p_high'])) ? trim($_POST['p_high']) : null; $up_description=(!empty($_POST['p_description'])) ?trim($_POST['p_description']) : null;$up_type_id=(string)$_POST['p_type_id'];echo $pid; echo $up_type_id; $temp=null;$query="UPDATE product SETp_name='".$up_name."',p_code='".$up_code."',p_type_id='".$up_type_id."',p_colour='".$up_colour."',p_width='".$up_width."',p_high='".$up_high."',p_description='".$up_description."',p_price='".$up_price."' WHERE product.product_id='".$pid."'"; // require ('Function/connection.php');//$stmt = mysqli_prepare($dbc,$query);//mysqli_stmt_bind_param($stmt,'ssssddsd',$up_name,$up_code,$up_type_id,$up_colour,$up_width,$up_high,$up_description,$up_price); // mysqli_stmt_execute($stmt);$stmt = mysqli_prepare($dbc,$query);mysqli_stmt_bind_param($stmt,'ssssddsd',$up_name,$up_code,$up_type_id,$up_colour,$up_width,$up_high,$up_description,$up_price);mysqli_stmt_execute($stmt);if(mysqli_stmt_affected_rows($stmt)==1){echo "<p> Product updated</p>"; echo 'Image of the product wich has not been changed willremind the same.';$_POST=array(); } else{ echo "<p> Error try again</p> "; } }mysqli_stmt_close($stmt);}