<?php
session_start();
include('./config.inc.php');
if($_SESSION['userid'] != '' && $_SESSION['user'] != ''){
header('Location: ./save.php');
exit;
}
$c = $_GET['c'];
$p = $_GET['p'];
if($c == 'login'){
$user = htmlspecialchars($_POST['username'], ENT_QUOTES);
$pass = htmlspecialchars($_POST['password'], ENT_QUOTES);
$save = $_POST['save'];
if($user != '' && $pass != ''){
$usdb = mysql_query("Select * From user Where username = '$user'");
$uanz = mysql_num_rows($usdb);
$uaus = mysql_fetch_array($usdb);
$upas = $uaus['password'];
$uid = $uaus['id'];
if($uanz == 1){
if(md5($pass) == $upas){
$_SESSION['userid'] = $uid;
$_SESSION['user'] = $user;
if($save == '1'){
setcookie("U16285", $user, time()+3600*24*30);
setcookie("P15212", md5($pass), time()+3600*24*30);
}
header('Location: ./save.php');
exit;
} else {
$error = '<span class="error">Passwort wurde falsch eingegeben!</span>';
}
} else {
$error = '<span class="error">User konnte nicht gefunden werden!</span>';
}
} else {
$error = '<span class="error">Bitte fülle die Felder aus!</span>';
}
}
if($_COOKIE['U16285'] != '' && $_COOKIE['P15212'] != ''){
$user = htmlspecialchars($_COOKIE['U16285'], ENT_QUOTES);
$pass = htmlspecialchars($_COOKIE['P15212'], ENT_QUOTES);
if($user != '' && $pass != ''){
$usdb = mysql_query("Select * From user Where username = '$user'");
$uanz = mysql_num_rows($usdb);
$uaus = mysql_fetch_array($usdb);
$upas = $uaus['password'];
$uid = $uaus['id'];
if($uanz == 1){
if($pass == $upas){
$_SESSION['userid'] = $uid;
$_SESSION['user'] = $user;
header('Location: ./save.php');
exit;
} else {
$error = '<span class="error">Passwort wurde falsch eingegeben!</span>';
}
} else {
$error = '<span class="error">User konnte nicht gefunden werden!</span>';
}
} else {
$error = '<span class="error">Bitte fülle die Felder aus!</span>';
}
}
if($c == 'regist'){
$username = $_POST['username'];
$password = $_POST['password'];
$passconf = $_POST['passwordconfirm'];
$email = $_POST['email'];
$captcha = $_POST['captcha'];
if($username != '' && $password != '' && $passconf != '' && $email != '' && $captcha != ''){
if(md5($password) == md5($passconf)){
if(md5($_POST['captcha']) == $_SESSION['random_txt']){
unset($_POST['captcha'],$_SESSION['random_txt']);
$usdb = mysql_query("Select * From user Where username = '$username'");
$uanz = mysql_num_rows($usdb);
if($uanz == 0){
$password = md5($password);
$insert = mysql_query("Insert Into user (username, email, password) Values ('$username', '$email', '$password')");
if($insert){
header('Location: ./');
exit;
} else {
$error = '<span class="error">Fehler beim erstellen des Accounts!</span>';
}
} else {
$error = '<span class="error">Username schon vorhanden! Bitte wähle einen anderen.</span>';
}
} else {
$erro = '<span class="error">Captcha ist falsch!</span>';
}
} else {
$error = '<span class="error">Passwörter stimmen nicht überein!</span>';
}
} else {
$error = '<span class="error">Bitte alle Felder ausfüllen!</span>';
}
}