if ((isset($HTTP_POST_VARS["MM_insert"])) && ($HTTP_POST_VARS["MM_insert"] == "form2")) {
$insertSQL = sprintf("INSERT INTO orders (cqty, cprod, cprice, cid, size, color, style, cdate, ctime, ship_rate, no_ship, prod_wt, xstatus) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($HTTP_POST_VARS['qty'], "int"),
GetSQLValueString($HTTP_POST_VARS['prod'], "text"),
GetSQLValueString($HTTP_POST_VARS['price'], "text"),
GetSQLValueString($HTTP_POST_VARS['orderid'], "text"),
GetSQLValueString($HTTP_POST_VARS['size'], "text"),
GetSQLValueString($HTTP_POST_VARS['color'], "text"),
GetSQLValueString($HTTP_POST_VARS['style'], "text"),
GetSQLValueString($HTTP_POST_VARS['date'], "text"),
GetSQLValueString($HTTP_POST_VARS['time'], "text"),
GetSQLValueString($HTTP_POST_VARS['shipping'], "double"),
GetSQLValueString($HTTP_POST_VARS['no_ship'], "text"),
GetSQLValueString($HTTP_POST_VARS['prod_wt'], "double"),
GetSQLValueString($HTTP_POST_VARS['xstatus'], "text"));
mysql_select_db($database_V3, $V3);
$Result1 = mysql_query($insertSQL, $V3) or die(mysql_error());
$insertGoTo = "inventory.php?oid=$boid";
if (isset($HTTP_SERVER_VARS['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $HTTP_SERVER_VARS['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
mysql_select_db($database_V3, $V3);
$query_Recordset4 = "SELECT * FROM defcat";
$Recordset4 = mysql_query($query_Recordset4, $V3) or die(mysql_error());
$row_Recordset4 = mysql_fetch_assoc($Recordset4);
$totalRows_Recordset4 = mysql_num_rows($Recordset4);
$defcat=$row_Recordset4['cdef'];
mysql_select_db($database_V3, $V3);
$query_Recordset1 = "SELECT DISTINCT(ccat) FROM products ORDER BY ccat ASC";
$Recordset1 = mysql_query($query_Recordset1, $V3) or die(mysql_error());
$row_Recordset1 = mysql_fetch_assoc($Recordset1);
$totalRows_Recordset1 = mysql_num_rows($Recordset1);
if (isset($HTTP_GET_VARS['pageNum_Recordset2'])) {
$pageNum_Recordset2 = $HTTP_GET_VARS['pageNum_Recordset2'];
}
$startRow_Recordset2 = $pageNum_Recordset2 * $maxRows_Recordset2;
$maxRows_Recordset2 = 4;
$pageNum_Recordset2 = 0;
if (isset($HTTP_GET_VARS['pageNum_Recordset2'])) {
$pageNum_Recordset2 = $HTTP_GET_VARS['pageNum_Recordset2'];
}
$startRow_Recordset2 = $pageNum_Recordset2 * $maxRows_Recordset2;
if(!isset($HTTP_GET_VARS['search']) OR $HTTP_GET_VARS['search']==""){
$colname_Recordset2 = "1";
if (isset($HTTP_GET_VARS['CatId'])) {
$colname_Recordset2 = (get_magic_quotes_gpc()) ? $HTTP_GET_VARS['CatId'] : addslashes($HTTP_GET_VARS['CatId']);
}
if (!isset($HTTP_GET_VARS['CatId'])) {
$colname_Recordset2 = (get_magic_quotes_gpc()) ? $defcat : addslashes($defcat);
}
mysql_select_db($database_V3, $V3);
$query_Recordset2 = sprintf("SELECT * FROM products WHERE ccat = '%s' AND show_hide = 'yes' AND cinv <> '0' ORDER BY cprice ASC", $colname_Recordset2);
$query_limit_Recordset2 = sprintf("%s LIMIT %d, %d", $query_Recordset2, $startRow_Recordset2, $maxRows_Recordset2);
$Recordset2 = mysql_query($query_limit_Recordset2, $V3) or die(mysql_error());
$row_Recordset2 = mysql_fetch_assoc($Recordset2);
}
if(isset($HTTP_GET_VARS['search']) AND $HTTP_GET_VARS['search']!=""){
$colname_Recordset2 = "1";
if (isset($HTTP_GET_VARS['search'])) {
$colname_Recordset2 = (get_magic_quotes_gpc()) ? $HTTP_GET_VARS['search'] : addslashes($HTTP_GET_VARS['search']);
}
mysql_select_db($database_V3, $V3);
$query_Recordset2 = sprintf("SELECT * FROM products WHERE xkey LIKE '%%%s%%' AND show_hide = 'yes' AND cinv <> '0' ORDER BY cprice ASC", $colname_Recordset2);
$query_limit_Recordset2 = sprintf("%s LIMIT %d, %d", $query_Recordset2, $startRow_Recordset2, $maxRows_Recordset2);
$Recordset2 = mysql_query($query_limit_Recordset2, $V3) or die(mysql_error());
$row_Recordset2 = mysql_fetch_assoc($Recordset2);
}
if (isset($HTTP_GET_VARS['totalRows_Recordset2'])) {
$totalRows_Recordset2 = $HTTP_GET_VARS['totalRows_Recordset2'];
} else {
$all_Recordset2 = mysql_query($query_Recordset2);
$totalRows_Recordset2 = mysql_num_rows($all_Recordset2);
}
$totalPages_Recordset2 = ceil($totalRows_Recordset2/$maxRows_Recordset2)-1;
$maxRows_Recordset3 = 10;
$pageNum_Recordset3 = 0;
if (isset($HTTP_GET_VARS['pageNum_Recordset3'])) {
$pageNum_Recordset3 = $HTTP_GET_VARS['pageNum_Recordset3'];
}
$startRow_Recordset3 = $pageNum_Recordset3 * $maxRows_Recordset3;
$MMColParam_Recordset3 = "1";
if (isset($HTTP_GET_VARS['CatId'])) {
$MMColParam_Recordset3 = (get_magic_quotes_gpc()) ? $HTTP_GET_VARS['CatId'] : addslashes($HTTP_GET_VARS['CatId']);
}
$MMColPara_Recordset3 = "1";
if (isset($yes)) {
$MMColPara_Recordset3 = (get_magic_quotes_gpc()) ? "yes" : addslashes("yes");
}
mysql_select_db($database_V3, $V3);
$query_Recordset3 = sprintf("SELECT * FROM products WHERE ccat = '%s' AND show_hide = '%s' ORDER BY cprice ASC", $MMColParam_Recordset3,$MMColPara_Recordset3);
$query_limit_Recordset3 = sprintf("%s LIMIT %d, %d", $query_Recordset3, $startRow_Recordset3, $maxRows_Recordset3);
$Recordset3 = mysql_query($query_limit_Recordset3, $V3) or die(mysql_error());
$row_Recordset3 = mysql_fetch_assoc($Recordset3);
if (isset($HTTP_GET_VARS['totalRows_Recordset3'])) {
$totalRows_Recordset3 = $HTTP_GET_VARS['totalRows_Recordset3'];
} else {
$all_Recordset3 = mysql_query($query_Recordset3);
$totalRows_Recordset3 = mysql_num_rows($all_Recordset3);
}
$totalPages_Recordset3 = ceil($totalRows_Recordset3/$maxRows_Recordset3)-1;
$colname_Recordset_order = "1";
if (isset($HTTP_GET_VARS['oid'])) {
$colname_Recordset_order = (get_magic_quotes_gpc()) ? $HTTP_GET_VARS['oid'] : addslashes($HTTP_GET_VARS['oid']);
}
mysql_select_db($database_V3, $V3);
$query_Recordset_order = sprintf("SELECT * FROM orders WHERE cid = '%s'", $colname_Recordset_order);
$Recordset_order = mysql_query($query_Recordset_order, $V3) or die(mysql_error());
$row_Recordset_order = mysql_fetch_assoc($Recordset_order);
$totalRows_Recordset_order = mysql_num_rows($Recordset_order);
$colname_total = "1";
if (isset($HTTP_GET_VARS['oid'])) {
$colname_total = (get_magic_quotes_gpc()) ? $HTTP_GET_VARS['oid'] : addslashes($HTTP_GET_VARS['oid']);
}
mysql_select_db($database_V3, $V3);
$query_total = sprintf("SELECT SUM(cqty*cprice) FROM orders WHERE cid = '%s'", $colname_total);
$total = mysql_query($query_total, $V3) or die(mysql_error());
$row_total = mysql_fetch_assoc($total);
$totalRows_total = mysql_num_rows($total);
$queryString_Recordset2 = "";
if (!empty($HTTP_SERVER_VARS['QUERY_STRING'])) {
$params = explode("&", $HTTP_SERVER_VARS['QUERY_STRING']);
$newParams = array();
foreach ($params as $param) {
if (stristr($param, "pageNum_Recordset2") == false &&
stristr($param, "totalRows_Recordset2") == false) {
array_push($newParams, $param);
}
}
if (count($newParams) != 0) {
$queryString_Recordset2 = "&" . implode("&", $newParams);
}
}
$queryString_Recordset2 = sprintf("&totalRows_Recordset2=%d%s", $totalRows_Recordset2, $queryString_Recordset2);
$queryString_Recordset3 = "";
if (!empty($HTTP_SERVER_VARS['QUERY_STRING'])) {
$params = explode("&", $HTTP_SERVER_VARS['QUERY_STRING']);
$newParams = array();
foreach ($params as $param) {
if (stristr($param, "pageNum_Recordset3") == false &&
stristr($param, "totalRows_Recordset3") == false) {
array_push($newParams, $param);
}
}
if (count($newParams) != 0) {
$queryString_Recordset3 = "&" . implode("&", $newParams);
}
}
$queryString_Recordset3 = sprintf("&totalRows_Recordset3=%d%s", $totalRows_Recordset3, $queryString_Recordset3);
$colname_Recordsetda2 = "1";
if (isset($d2)) {
$colname_Recordsetda2 = (get_magic_quotes_gpc()) ? $d2 : addslashes($d2);
}
mysql_select_db($database_V3, $V3);
$query_Recordsetda2 = sprintf("DELETE FROM orders WHERE xstamp < '%s' AND xstatus = 'temp'", $colname_Recordsetda2);
$Recordsetda2 = mysql_query($query_Recordsetda2, $V3) or die(mysql_error());
$colname1_Recordsetda2 = "1";
if (isset($cdate)) {
$colname1_Recordsetda2 = (get_magic_quotes_gpc()) ? $cdate : addslashes($cdate);
}
mysql_select_db($database_V3, $V3);
$query_Recordsetda2 = sprintf("DELETE FROM orders WHERE cdate < '%s' AND xstatus = 'temp'", $colname1_Recordsetda2);
$Recordsetda2 = mysql_query($query_Recordsetda2, $V3) or die(mysql_error());
if ((isset($HTTP_POST_VARS['pid'])) && ($HTTP_POST_VARS['pid'] != "")) {
$xccat=$HTTP_POST_VARS['catid'];
$xxc=$HTTP_POST_VARS['oid'];
$deleteSQL = sprintf("DELETE FROM orders WHERE id=%s",
GetSQLValueString($HTTP_POST_VARS['pid'], "int"));
mysql_select_db($database_V3, $V3);
$Result1 = mysql_query($deleteSQL, $V3) or die(mysql_error());
if($HTTP_POST_VARS['search']==""){
header("Location: cart.php?CatId=$xccat&oid=$xxc&pageNum_Recordset2=$ppg");
}
if($HTTP_POST_VARS['search']!=""){
header("Location: cart.php?search=$xsearch&oid=$xxc&pageNum_Recordset2=$ppg");
}
}
?>