realEscapeSingle($_POST['new_price_hourly']); $new_price_monthly = $db->realEscapeSingle($_POST['new_price_monthly']); $new_price_year = $db->realEscapeSingle($_POST['new_price_year']); $new_url = $db->realEscapeSingle($_POST['new_url']); $service = $db->realEscapeSingle($_POST['service']); //Create INSERT query $qry_change_url = "UPDATE OGP_DB_PREFIXbilling_services SET price_hourly ='".$new_price_hourly."', price_monthly ='".$new_price_monthly."', price_year ='".$new_price_year."', img_url ='".$new_url."' WHERE service_id=".$service; $db->query($qry_change_url); } //Querying INSERT new service INTO DB if(isset($_POST['mod_cfg_id']) AND isset($_POST['remote_server_id']) AND isset($_POST['slot_max_qty']) AND isset($_POST['price_hourly']) AND isset($_POST['price_monthly']) AND isset($_POST['price_year'])) { //Sanitize the POST values $home_cfg_id = $db->realEscapeSingle($_POST['home_cfg_id']); $mod_cfg_id = $db->realEscapeSingle($_POST['mod_cfg_id']); $service_name = $db->realEscapeSingle($_POST['service_name']); $remote_server_id = $db->realEscapeSingle($_POST['remote_server_id']); $slot_max_qty = $db->realEscapeSingle($_POST['slot_max_qty']); $slot_min_qty = $db->realEscapeSingle($_POST['slot_min_qty']); $price_hourly = $db->realEscapeSingle($_POST['price_hourly']); $price_monthly = $db->realEscapeSingle($_POST['price_monthly']); $price_year = $db->realEscapeSingle($_POST['price_year']); $description = $db->realEscapeSingle($_POST['description']); $img_url = $db->realEscapeSingle($_POST['img_url']); $ftp = $db->realEscapeSingle($_POST['ftp']); $install_method = $db->realEscapeSingle($_POST['install_method']); $manual_url = $db->realEscapeSingle($_POST['manual_url']); $access_rights = ""; if(isset($_POST['allow_updates']))$access_rights .= $db->realEscapeSingle($_POST['allow_updates']); if(isset($_POST['allow_file_management']))$access_rights .= $db->realEscapeSingle($_POST['allow_file_management']); if(isset($_POST['allow_parameter_usage']))$access_rights .= $db->realEscapeSingle($_POST['allow_parameter_usage']); if(isset($_POST['allow_extra_params']))$access_rights .= $db->realEscapeSingle($_POST['allow_extra_params']); if(isset($_POST['allow_ftp_usage']))$access_rights .= $db->realEscapeSingle($_POST['allow_ftp_usage']); if(isset($_POST['allow_custom_fields']))$access_rights .= $db->realEscapeSingle($_POST['allow_custom_fields']); $qry_add_service = "INSERT INTO OGP_DB_PREFIXbilling_services(service_id, home_cfg_id, mod_cfg_id, service_name, remote_server_id, slot_max_qty , slot_min_qty, price_hourly, price_monthly, price_year, description, img_url, ftp, install_method, manual_url, access_rights) VALUES(NULL, '".$home_cfg_id."', '".$mod_cfg_id."', '".$service_name."', '".$remote_server_id."', '".$slot_max_qty."', '".$slot_min_qty."', '".$price_hourly."', '".$price_monthly."', '".$price_year."', '".$description."', '".$img_url."', '".$ftp."', '".$install_method."', '".$manual_url."', '".$access_rights."')"; $db->query($qry_add_service); } //Querying REMOVE service FROM DB if (isset($_POST['service_id'])) { $db->query( "DELETE FROM OGP_DB_PREFIXbilling_services WHERE service_id=" . $db->realEscapeSingle($_POST['service_id']) ); } ?>