The Validation page looks like:
<?php
session_start();
require_once 'conn.php';
if ($REQUEST['Action'] = "Edit") {
//Set Values for Errors
$Error = '';
$Msg = "Y";
$SESSION['Customer_ID'] = $POST['Customer_ID'];
$SESSION['Details'] = $POST['Details'];
$SESSION['JobNo'] = $POST['JobNo'];
$SESSION['Supervisor'] = $POST['Supervisor'];
$SESSION['PerformState'] = $POST['PerformState'];
$SESSION['Cost'] = $POST['Cost'];
$SESSION['Sell'] = $POST['Sell'];
$SESSION['WonLost'] = $POST['WonLost'];
$SESSION['Win'] = $POST['Win'];
$SESSION['EAwardDate'] = $POST['EAwardDate'];
$SESSION['ManDays'] = $POST['ManDays'];
if (empty($SESSION['JobNo'])) {
$SESSION['JobNo'] = 'P';
}
if($SESSION['JobNo'] != "P") {
$SESSION['Win'] = 100;
}
if(empty($POST['Customer_ID'])) {
$Error .= "C=".$Msg."&";
}
if(empty($POST['Details'])) {
$Error .= "D=".$Msg."&";
}
if(empty($POST['Supervisor'])) {
$Error .= "S=".$Msg."&";
}
if(empty($POST['PerformState'])) {
$Error .= "P=".$Msg."&";
}
if(empty($POST['Cost'])) {
$SESSION['Cost'] = 0;
}
if (!is_numeric($SESSION['Cost'])) {
$Error .="CO=".$Msg."&";
}
if(empty($POST['Sell'])) {
$SESSION['Sell'] = 0;
}
if (!is_numeric($SESSION['Sell'])) {
$Error .="Se=".$Msg."&";
}
If (!empty($POST['EAwardDate'])) {
if (ereg("([0-9]{2})/([0-9]{2})/([0-9]{4})", $POST['EAwardDate'], $reg)) {
$EAD = $reg[3]."-".$reg[2]."-".$reg[1];
}elseif (ereg("([0-9]{4})-([0-9]{2})-([0-9]{2})", $POST['EAwardDate'], $reldatepart)) {
$EAD = $POST['EAwardDate'];
}else {
$Error .="EAD=422&";
}
}else{
$EAD = '';
}
if(empty($POST['ManDays'])) {
$SESSION['ManDays'] = 0;
}
if (!is_numeric($SESSION['ManDays'])) {
$Error .= "MD=".$Msg."&";
}
if (!empty($Error)) {
header("location:index.php?Page=OpReg&Link=EditQuote&Action=Edit&ID=".$GET['ID']."&".$Error);
}else{
$Insert = "UPDATE tbl_Quote_Register SET
fld_Date_Created = '".$SESSION['DateCreated']."',
fld_Quote_Number = '".$SESSION['QuoteNo']."',
fld_Customer_ID = '".$SESSION['Customer_ID']."',
fld_Details = '".$SESSION['Details']."',
fld_Job_Number = '".$SESSION['JobNo']."',
fld_Supervi = '".$SESSION['Supervisor']."',
fld_Perform_State = '".$SESSION['PerformState']."',
fld_Cost_Amount = '".$SESSION['Cost']."',
fld_Sell_Amount = '".$SESSION['Sell']."',
fld_Won = '".$SESSION['WonLost']."',
fld_Win_Percentage = '".$SESSION['Win']."',
fld_Estimated_Award_Date = '".$EAD."',
fld_Man_Days = '".$SESSION['ManDays']."'
WHERE
fld_ID ='".$_REQUEST['ID']."'";
$result = mysql_query($Insert) or die(mysql_error());
header("location:index.php?Page=OpReg&Link=Current&Success=Y");
}
}