Tak jsem se na to vrhl a vymyslel tohle
define("HLAVNI", basename($_SERVER['PHP_SELF']));
mysql_connect("$bd_host","$db_user","$db_pass");
mysql_select_db("$db_name");
if(isset($_GET["odeslat"])) {
$sel = mysql_query("SELECT * FROM Kontakty ORDER BY ID DESC");
$id = mysql_fetch_array($sel);
$id[ID]++;
mysql_query("INSERT INTO Kontakty (Jmeno, Prijmeni, Email, Mobil, ID) VALUES ('$_POST[jmeno]', '$_POST[prijmeni]', '$_POST[email]', '$_POST[mobil]', '$id[ID]')");
echo "<div align='center'>Zápis do DB byl úspěšný</div>";
?><br /><br /><div align='center'><input type='button' onCLICK="location.href = '<?php HLAVNI ?>?upravit'" value='Pokračovat'></div><?php
}
elseif (isset($_GET["novy"])) {
echo "<center>";
echo "<form action='".HLAVNI."?odeslat' method='post'>";
echo "Jméno:<br />";
echo "<input type='text' name='jmeno' /><br /><br />";
echo "Přijmení:<br />";
echo '<input type="text" name="prijmeni" /><br /><br />';
echo "Email:<br />";
echo '<input type="text" name="email" /><br /><br />';
echo "Tel. číslo:<br />";
echo '<input type="text" name="mobil" /><br />';
echo '<input type="submit" value="Uložit" />';
echo "</form></center>";
}
elseif (isset($_GET["upravit"])) {
$res = mysql_query("SELECT * FROM `Kontakty` ORDER BY ID ASC");
echo "<table align='center' cellpadding='0' cellspacing='0' border='1'>";
echo "<center><tr><th width='75'>Jméno</th>";
echo "<th width='75'>Příjmení</th>";
echo "<th width='120'>Email</th>";
echo "<th width='100'>Mobil</th></tr></center>";
$db = mysql_query("select ID from Kontakty order by ID ASC LIMIT 1");
$a = mysql_fetch_array($db);
while($row = mysql_fetch_array($res))
{
echo "<tr>";
echo "<td>".$row['Jmeno']."</td>";
echo "<td>".$row['Prijmeni']."</td>";
echo "<td>".$row['Email']."</td>";
echo "<td>".$row['Mobil']."</td>";
$db = mysql_query("select ID from Kontakty order by ID ASC");
{
echo "<td>";
echo '<a href="?smazat&ID='.$a["ID"].'">Smazat</a>';
$a[ID]++;
echo "</td></tr>";
}
}
echo "</table>";
}
elseif (isset($_GET["smazat"]))
{
$id = $_GET['ID'];
mysql_query("delete from Kontakty where ID = '$id'");
header("Location: ".HLAVNI."?upravit");
}
?>
<br /><br /><br /><br />
<div align='center' style='margin-bottom: top'><input type='button' value='Upravit' onClick = "location.href = '<?php HLAVNI ?>?upravit'">
<input type='button' value='Nový kontakt' onClick = "location.href = '<?php HLAVNI ?>?novy'">
<input type='button' value='Smazat' onClick = "location.href = '<?php HLAVNI ?>?smazat'"></div>
<div align='center' style='margin-bottom: top'><input type='button' value='Domů' onClick = "location.href = '<?php HLAVNI ?>'"></div>
<?php
} else {echo "<div align='center'>Nemáš sem přístup!</div>";}
Je tam ještě nějaká bezbečnostní chyba?