<?php
session_start();
include("header.php");
require_once("function.php");
require_once("config.php");
$admintest="0";
echo "<table width=\"100%\">
<td align=\"right\" valign=\"top\">";
/*********************************/
#insert right block
/*********************************/
echo "</td>";
/*********************************/
$select = mysql_query("SELECT * FROM `administrator` ") or die ("NOT");
$num_rows = mysql_num_rows($select);
login_form();
////////////////////////////////////////////////////////////////////////////////
#insert Left Blocks :
/******************************/
echo "</table>";
function switch_admin()
{
global $username,$password,$user,$pwd,$admintest;
echo "<table width=\"100%\">
<td align=\"right\" valign=\"top\">";
include("blocks/admin.php");
echo "</td>
<td align=\"center\" valign=\"top\">";
$value = check($_GET["do"], "get");
switch($value)
{
case "sttings" :
include('admin/settings.php');
break;
case "about" :
include('admin/about.php');
break;
case "domain" :
include('admin/domain.php');
break;
case "hesab" :
include('admin/hesab.php');
break;
case "support" :
include('admin/support.php');
break;
case "news" :
include('admin/news.php');
break;
case "sttings" :
include('admin/settings.php');
break;
case "sttings" :
include('admin/settings.php');
break;
default:
include('admin/settings.php');
break;
}
echo "</table>";
}
/************************************/
//بررسیه اطلاعات ورودی
function check($value, $Get_or_Post)
{
$return_val = "";
if ($Get_or_Post=="get")
{
$return_val = (isset($_GET[$value]) && !empty($_GET[$value])) ? quote_smart(trim($_GET[$value])) : "";
}
else if ($Get_or_Post=="post")
{
$return_val = (isset($_POST[$value]) && !empty($_POST[$value])) ? quote_smart(trim($_POST[$value])) : "";
}
return $return_val;
}
/************************************/
function quote_smart($value)
{
// Stripslashes
if (get_magic_quotes_gpc())
{
$value = stripslashes($value);
}
// Quote if not a number or a numeric string
if (!is_numeric($value))
{
$value = mysql_real_escape_string($value);
}
return $value;
}
/************************************/
function login_form()
{
global $username,$password,$user,$pwd,$admintest;
echo "<table width=\"100%\">";
echo "<td align=\"right\" valign=\"top\">";
echo "</td>";
OpenTable("ورود به بخش مدیریت","50%");
if ( !isset($_SESSION["UserName"]) || !isset($_SESSION["PassWord"]) ||
empty($_SESSION["UserName"]) || empty($_SESSION["PassWord"]))
{
?>
<form action="<?php $_SERVER['PHP_SELF']; ?>" name="login" method="post" >
<table width="100%" >
<td align="right" width="50%" class="register_td1"> نام کاربری :</td>
<td align="center" width="50%" class="register_td2"><input type="text" name="username" class="register_textbox" /></td>
<tr>
<td class="register_td1" align="right" width="50%"> رمز عبور :</td>
<td align="center" width="50%" class="register_td2" ><input type="password" name="password" class="register_textbox" /></td>
</tr>
</table>
<tr>
<td width="50%" align="center"><input class="btn" onclick="" type="submit" name="subm" value="ورود" /></td>
</tr>
</form>
<?php
}
$username = check($_POST['username'], "post");
$password = check($_POST['password'], "post");
$_SESSION["UserName"] = $username;
$_SESSION["PassWord"] = $password;
CloseTable();
if($_POST['subm']) check_login();
echo "</table>";
}
/************************************/
function check_login()
{
global $username, $password, $user, $pwd, $admintest;
$select=mysql_query("SELECT * FROM `administrator` WHERE( user='$username' AND pwd='$password' )") or die ("NOT");
while($rows = mysql_fetch_array($select))
{
$user = $rows[$user];
$pwd = $rows[$pwd];
echo "$user<br />$pwd";
switch_admin();
}
}
?>