| Server IP : 210.245.233.93 / Your IP : 216.73.216.226 Web Server : Apache/2.2.15 (CentOS) System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64 User : apache ( 48) PHP Version : 5.3.3 Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/www/onesupportdemo.onesolution.hk/user_bk/ |
Upload File : |
<?php
require_once(__DIR__ . '/../checkuser.php');
if (isPost()) {
extract($_POST);
if (isset($id, $loginpw, $loginpw2)) {
// Validation
$errors = array();
if ($loginpw != $loginpw2) {
$errors['loginpw'] = 'Password and Re-enter password are not match.';
}
if ($id != $_SESSION['webadmin']['id']) {
$errors['id'] = 'Not allow to modify other user password.';
}
if (!empty($errors)) {
$message = print_r($errors, true);
} else {
$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
$parameters = array('sys_login');
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$columns = $sth->fetchAll();
$post = $_POST;
foreach ($columns as $column) {
$column = $column['column_name'];
if (isset($post[$column])) {
$staff[$column] = $post[$column];
}
}
// Append record time
$now = date("Y-m-d H:i:s");
$staff = array_merge($staff, array(
'lastupdate' => $now,
'lastupby' => $_SESSION['webadmin']['id'],
));
// Update staff
$values = array();
$parameters = array();
foreach ($staff as $column => $value) {
if ($column != 'id') {
switch ($column) {
case 'loginpw':
$parameters[] = md5($value);
break;
default:
$parameters[] = !strlen($value) ? null : $value;
break;
}
$values[] = "`$column` = ?";
}
}
$sql = "UPDATE sys_login SET " . implode(', ', $values) . " WHERE id = ?";
$parameters[] = $staff['id'];
if (!($sth = $dbh->prepare($sql))) {
throw new Exception("sql prepare statement failure: $sql");
}
$sth->setFetchMode(PDO::FETCH_ASSOC);
if (!$sth->execute($parameters)) {
throw new Exception("sql execute statement failure: $sql");
}
$data = array(
'message' => 'Password changed, please sign in again.',
'message_heading' => 'Notice',
'message_css_class' => 'alert-success',
);
redirectAndExit(Util::link(__DIR__ . '/../logout.php') . '?' . http_build_query($data));
}
}
}