0byt3m1n1
Path:
/
home
/
k
/
a
/
s
/
kassiope
/
www
/
achat
/
[
Home
]
File: commander_cadeau.php
<? include("../configuration.inc.php"); $DOC_TITLE = "GAIABOUTIK.FR"; $SQL = "SELECT * FROM gaia_utilisateurs WHERE id_utilisateur = '".$_SESSION['utilisateur']['id_utilisateur']."'"; $RESULT = mysql_query_override($SQL); $u = mysql_fetch_object_override($RESULT); include("$repertoire_modele/haut.php"); echo "<div class=\"normal\">"; echo "<div class=\"entete\">".strtoupper(ORDER_GIFT)."</div><br />"; if ($u->points > $_POST['points_cadeau']) { $email = $u->email; $adresse_client = addslashes($u->prenom)." ".addslashes($u->nom_famille)."\n"; $adresse_client .= addslashes($u->adresse)."\n"; $adresse_client .= $u->code_postal." ".addslashes($u->ville)."\n"; $adresse_client .= "Tel : ".$u->telephone."\n"; /* Création de la commande cadeau */ mysql_query_override("INSERT INTO gaia_commandes_cadeaux ( email , nom_cadeau , points_cadeau , adresse_client , date_commande , lang ) VALUES ( '".$email."' , '".addslashes($_POST['nom_cadeau'])."' , '".addslashes($_POST['points_cadeau'])."' , '".$adresse_client."' , '".date("Y-m-d H:i:s")."' ,'".$_SESSION['langue']."')"); $commandeid_cadeau = mysql_insert_id_override(); /* Supprime les points du compte client */ mysql_query_override("UPDATE gaia_utilisateurs SET points = points - '".addslashes($_POST['points_cadeau'])."' WHERE id_utilisateur = '".$_SESSION['utilisateur']['id_utilisateur']."'"); echo ORDER_RESUME." - ".ORDER_REFERENCE." : ".$commandeid_cadeau."<br /><br />"; echo stripslashes(MSG_ORDER_GIFT)."<br /><br />"; echo nl2br(stripslashes($adresse_client))."<br /><br />"; $SQL = "SELECT * FROM gaia_utilisateurs WHERE id_utilisateur = '".$_SESSION['utilisateur']['id_utilisateur']."'"; $RESULT = mysql_query_override($SQL); $u = mysql_fetch_object_override($RESULT); $_SESSION['utilisateur']['points'] = $u->points; echo POINT_REMAIN." : ".$u->points."<br /><br />"; echo "<li><a href=\"$wwwroot/achat/catalogue_cadeaux.php\" class=\"normal\">".GIFT_CATALOGUE."</a></li><br /><br />"; echo THANKS.", $site."; } else { echo MSG_ERROR_ORDER_GIFT."<br /><br />"; echo "<li>".POINT_REMAIN." : ".$u->points."</li><br /><br />"; echo "<li><a href=\"$wwwroot/achat/catalogue_cadeaux.php\" class=\"normal\">".LOOK_GIFT_CATALOGUE."</a></li><br /><br />"; echo THANKS.", $site."; } echo "</div>"; include("$repertoire_modele/bas.php"); ?>