Frage zum Aufruf von einer Base64 kodierten Funktion

hanow

Mitglied
Guten Tag, alle

Ich möchte ein Programm schreiben, welches eine Funktion aus einer anderen PHP-Datei aufruft, die aber in base64 kodiert wurde. Ich bekomme immer den Fehler dass die aufgerufene Funktion nicht definiert ist.

Die Base64 kodierte Funktionen habe ich wieder online dekodiert um zu wissen, ob die Funktion exisitiert.

Code-Teil:

func.inc.php

PHP:
<?ob_start(); $a='eNrtPVub27axz82vgPltQ8nWbe0kTfYid23L9rb2rrOS3aTeDT9KglbsUqRMUl7bid/O/zgv/Q3nqW/+Y2dmcCFAUpe1123aJl9ii8BgMBgMMBcMkHjo8WjsjULuR7X67t3u3t35dP5FytM0iCMvzfwkg3KW8FeLIOFeHI04c+d+ml6OW0E0agG0W6wexVHER5lRD7/CxZizmttqteFfKG3O/CDkSXsUAjIEE9/UADqcLKJRBiSwd4uJH4ZpmiVBdF7bCn0enXO2z7a/q7Of2dY7HoymPIICd/v2na++/uYP337X8YejMZ+cT4O/XYSzKJ6/StJs8fryzdt3B/fuP+g9fPT48E9/fvL06PjZ9yf9wfMXf/nhx78ClVuyL090hjix1I/e+dPQy3uC6pBHNdU3UhsnrLYVQF0HGgRsj0lC8evWLUGpjby1r4l/Ocu8xI/GtU6j1FuTbdfPdtl7YHG2SKIiGqzRrJr5F9wb+xn3bnvpqxB/1bYy/5y6HwNx/M08jMe85rQc6AlrdhXedA7osknN+X3nq3Hz953b4g+EG7+8fUZ/bYu/Omf1dd1mweyTu2adzg79e1UaznkyA25qMvCXoAN+iOnzEj4P/RGQwwC706QuEGy3QK1VIxBDNZHDWsxtufAnUWV+dc52aW4zE9OOGMadMwMTyIDLqBFCQzvEspMXbJ9pJskm1qAf9QYPgLTbFtPz0S4bh8I4lh02rUGoLzFAJr/unFk9n/OMuP0VrNYrdDm7IBpBzMW/+Xzerp5W2pcWKQcBmS8y6ClIsrfY1ewtDNpLgYzR1E/g75q7yCbfug12//gIcAQTVkMiZ/55MPJeLeKMp975fFSrE6GEF4gVaBLuhx5PR/6cy2VVw7/mKWxNU56qbok0HqZ8Iwyykbl0qY09vikfXXhhfB7AdoLjBC7Q5honYyQUh3GDz+bZW1FdZ19+yVSBBqQhqS+kafy1UQviBiTiZtbvPendHzDRTzBusNdxEvkz3mCRP5qKX9zDfbgBi8TPFmmDjWAu2cOT46ckCQ/uec/7vROSjL887p30WK2G6AC7Q5JCH1DrsIOjB0zSkOlqTSSC1NnxCauJDhVEccK9Z8f9wUsXS9yz+saY6wRUE4PYd5472JX6OnDquK0nPF2EmZ7CVwueAFPhpylDoi5azLwkvgRJEI3qbB8UELE9W8x5qJFMeDaaen6S+G81LHTl9Xv9/uHxkRoIbiHUUBVYMDgRFoycJtdYkbJGzVsBAyflauFQRSVqsHkYXxIwiG4WwwdPajZ99iCCsYUaP616wWgLRhVZcLgZEBTtCnYfKHcWBlFg9xMQRP/wPoji497hoH//+EEvl/fnzx4cDHolwe33Bizk2buMJ2Lp7ZMIkbp0fmzOmmP2eCfYSWH/EoRJuRMCjwzx0hnoYCV7JtfEIiVwkDhbtvPFsZH4yV0jSxbc2HhkKdgAKRWvqCjsMtg7dMA95CTJbsW2sG65Y71gl8K0+YBwPRF5uHr0SipTrrbYtUurwZ7+2P/+iXfQ7x/flx1UrDVgvxQiLDlzcA8tSVFJjApQSh5zZFhyBpuYNU9E+4qpQJ0Uz9F4VMaRPQk3LeYfP+sdGcyHJpL38OtXxHckBw0rAeTCl8v2u3rl4jeod9jGIqscv7F8GKRWOX5j+dyH+fKKrfLSHKaIIS89M+wdpLIwHak5HaB7AS38CQ1JD8uO9G8or5gynIt/zqSxX35hKxRSxyTu8AgW7oAdHg2OS4S9OHjyvNdnNZushviEAZufMGbzUzOlXKgg658glLZImoupsA1Wb/F6hLjFI5Fq59UEM6RSleqxsXxYuT1hDZTlY7QhFI58tjXANSzS9fwoCDOopVygwZwTBhQJxoRPQ7LUJDbhsyKYpxxX+bEH2/wiykRlXZdLPxZ44k2hAfhsr/1Qm2jYq0d1XlEpYvOXEslZnYwJBJytQDLbBAnwfiklVLcpktkKJBtRoqVlKT0GxAYILZSztSivQOMqnhkQV0M4W4twIwpxZaDFJReilDTtEgte4Gen45rgYlVKcdDggrAKcHOxWzOnm5q8X4pA9mqytYCgQAE5c5bGyRnQsEffsEfXqKK+UUUR2Kr5Qld7BNlFonSTLUVvKOMgnYf+W28ah8EYNPtae+Xx8ZPDBwc/4pA/h2XCR9OYuXuZPww5o7jhviNpS50u0uCcRs6uhku6e9m0+yKO9trwN/6+F6T69/NpQjGa10a9KhsacM+QtxaUKDFhDi6QYeKzDf3mtMh4HgYsd9nlNADKa1e1sOrG2BNw3Pcd0P0iTiOxo5oBQsZd0zkE0RJ2ElYDWeNKCLKSlkKsbr+6rWGprYHReFwLcG+4yDKQwzgahcHoYt8Zc/DbOMa8aqfu0qGeuo1yre4Cagucq+8C79K5HymZSvjY6f6w18ayLuNRNgE3mcP0Cnq6gsDKeb51i+RVTFabJNUAWq271TIzdLYcF4jKksDIJIlnwj2Xg1wOmsWuVr0r9be7mYZ2N9PB7mZa1r26Hi022UBPulfXhO7VdZ3736LNZCBSSmkd/ZNcZMEMdoyda3q7+5BU0A3WZP2As6k/5BG74EHEYEUvZgx+nfNzPqRTjz2fTRM+2XdarTadQqWwL/O20323SL5cLGbh7uhir+3DMgTE7m5JZSB5tcIcAEWdHTpRIOfe5nheKcaxvHaTIXGmVIl/jYMy9oNlZz00ETIUoraEGzgVZuRYVqCxkG8bSzEipLQUDPDOboUjTMQtsQhUwFiBdXM3SftZFLZVBXsGgHYuKWZcBVFCgU2q+rBR7K+EMP29q0L8q9x8k+UlT7/oupu8lUXWmqkqXwZfGRuo2GY+NUiw1D4sqVfbbrSW6yGYt3yWr04ud6F0yBM8emX8TZBmAU/AGMSSLMX9Cf/LEv+8xe4FWcbBQuYptOyJUvYORpBmLPwyxrWc4gFu6xqWvWmSkwX0UaaCtpE2sxaUzVS/wlYvCXc33uhd2tWkLD+AbWTQW7N9yD73Vy/8/bJ0X4fAOQ/8VI7hIo4iEIAIRCVj5zz88H8p/gLXdswjDDOheFzyCL6ICSnKlI8TGLGD8SyIQLoSP4uTG05Zgp3jPzsVgeN5Eox4lRc2BwFNLcY9Onjae3AwOPhcrtjVg8Q6CisNfyTZPasYZToPeIiqs2qkuvLfa7Sa7NKI0fA/92cc1K1vLmcxpYVkhQYmK1AChVylkotkocoG43gBTgeZp1REpqjmWsl2NShDyEueZpTjUgAT5QIGhFdMEgUZCoBGpdxpcPOPFxVdqxptLn9+if5E1WrSoHWrMJGJXigWzmXOcF2k+aBLJK/1t8lXdEvdtfFuix4KeispsIliDWaKQAWJxiyVqWVaKop026JQNQqxw392TW/tIHo9rQ1YXZtQSfUoCV9P+dV3lNIoQblFSZ58IxGLU+xL2CMqcnTqu1VnkZ7YexBCpGZZ2VKlFByZDIXdA5/phB4jmUWSznY3jhUWPYM9ZVATCWWjfnk1tgZvR0EarW7sOx34p0n/LvEBqrtD1+9jWxar69coZJvsZVIorFNnnLV6WSI/XhDTMM6CaBJrEVLrb6PlZwiAuUcVGPc5tPqa/B6TgfJk+zVPJgt+PvQTcdysBprrxwZzlfZDiI6VM5Y3x1VTbqw0NW2m6F8P+YwnFwtKRZXUf0IIuWhKiQyvvA9zZk56oPxemJMTjLVuUGk/YJiouK2eHo+STVZMkmheAKugX0BUpngYGIxkI4xy3BeRneUAfademIlmnmJUMQ+3qmrNrDyrK81LzFUrEWLUwm50FCczmFLsB2iypjpXa6vFL/8uiJ0iH5MrdKdUoT/NxMRliSqThHNa3am02TZQD9K2w9rNLUqJqzICpdNyYakAzAqltZuvKQmYGwIFI9hYfJZpvkWjxe1nb3qne6fF+qNpAq4ceOZ3uhTCzzO9q/LF6IAzz8M1MmipL+F+12WK+EcgEB65QLCWgqDObgGt+bhvsm86dbkV0Dhb6LgDMpEgJtW5wFqJT9vz6TS+NEGrALELOQ+5hghM9WBF77Hpx3HVOGeq27H6T8Wp2S2iyaXuaEvRaeq04kvNyzAoPt39Ep0YUaGbAzZP6qToqzrf36BzC6auU4rF5FAQHH/cKKg7RwRw2AyEZgx/44lbNPSjixWBjcNpsjK0QTs39vbS3MfOcMBlTVhf1YBo3RrFYUx5x3hap8LTujBOMLLnWBnbqu4ctrXI0QfjFV3g7AhS7MXi7o2D1+qUEEulGiPBEfjFSawBlsQL4NUYNlMYZWXVcQTlX/xuj3ZQlr2d832H8A7jNw6DPXOhUi4DYWPiCXDeuyd6z5cwweAvE+rlmcPa2EvoD8FwgG1sLY7uXpuAu1/stYHqrvjzSijKvPKoMR64ZkkcnXdzb5P2FDr+lVXsBcyJiI/ivOxIv7U8XWSk0HQVKM5PXg1Het1k0unvJuQdydhftDiX3bPmR9FcJPX9Fch1uuzZwfN+j1WhWdIadXbiyPnM480C2nIR+Ti4JjPgV6ji/3O0uXL1l19uCuq7vyn935T+v0Tpl9U7+eflTbG+RE2vsSC6tj2gVX/BJBB2gqX0LX/NcsFcKyFI1zjdezItyFX4rVbu7sdYC59FFVqnjrSPg1/Nk9e8fRfsB2qvtw0iw49SjjdO22wI6mGIR5QRnkoyt5UPsuVW6Zlfh7LC4eCljJqUozFuA/b1Ybple+erBrvzbb186FC6/FKOgkisjpzDq1x/kZGbZRGnG+r44VdH+PsNImX6iiNgrrjhaJoQKOH0U192FsOWASER/Fil5kFpcx/2HwMV81O2dcHfirAIWszacC9pI6q2NdIK30RRqOnTwRI9ZKyoGDPHu1+1LfqLqIniyE9HAep65/TNt53m6ZvJBDVx9Crjbyjo+fKnU/hHQ552tr+G/26fOmcI9wrvulJr+OflTxqMKudJnMWwq6BY1O7uYK9ZvEMB5yhOZvKWpvvSb747aP610/zuLP/ptZpnNxGSLsqO9fV359QBVJK+X0T/9VunZD7QPbi5L65gEpTs5RcLSx1hx/EMb8JFEryaiJYHRJyetlzZIF0MFTygX9mkflM1ysJxoZOzn283vn4v64EGTbPZiUWhicihBXLO31ALxeO7+ehP/2jizXM859AKMGajac1p/yRwbLXRFBMCUdq5qFge8W8tuaJ38/Mt8o+49XWFyL6IFeeJUvnF0QKFtNBXkantX3EeuTdM2t296Vfdfl6+s9eGArcQK7cxVwWcz+kCdDlqbvSIyglHsOq5gbw3+3SdFDqS65pRUQs8DzG/X5sBYOdR0AyKTcRFo0xYbzvQX/eLF+L68A6zE7uNO8UEdiTvEu8suWGsAQ9E5jTaiOd8uAAnGEYijI6d4gkxNbDPm0XFF1jzDInfKR5W956fUDP8454yPGyqDMNN9SJ6MjIvgBu7dqZFNKb7uN40m+HGLG+6g3GTgZ00aYg2NOegVlJxpxFfFfDGnOwKUb+rWxSrZTHlSIh7vxG/ZM8eP3tKT5vUdEWzyw7T/tPBM6vocZzSxpTOsnkLjB+egM/bBPqbIx5lPGmN0arV4Nj+YJFNc52pap7La92I7JIPb3/TmW9vm02f5W8FOBd++KexPx2/S775g2MR+Hjw9EkNUZtEPkxizIB2YLcHmXz7x/V0YosjSc0TCc0eLiJ2n6AdoX5tnUlTI5afQnMwHsO/sFRTXW8yYzH8Gx+R3y9nwai8F4/fYo2cVanvdVOQi5p5ZL/2xnWVUG0qTyh76ZyPAj+klyuEUDVY72jgff/8eNDr2wJWhjekbMp9WIWpvnprlL3Em/HO08OnvSb4DviYzw7bbnWcIsT9GCYhypoYdtxhSEsbtpog2mXyYY19EPHmt0vbDcAyTSc8afYiWAQBLlSh/pv0qgtegKDbEUPklDBBKoSA7V0GMPdRtESeaM+0+kep2mE/a8TvSxT+0BTLbgdXYNuBfWI+nb8WvKjVV0vdyhltsGAm3zg5TcB9aeiO6/WK7C7pdpnJXatiWMvOy+SRnicMUpkzJUNZ8rqmgtT+Vh56WxEUkW8c0JUPtW0sCedppYHQSjMsB891R50uyIAHvgJa1AtY/XDCElhRLxPfwndlbkGhqBVvhCxBA5VKdYZ8sjJ5VgAI6PNFhrm9wQp4DSKvvxhBgiUtzFiEEM4gxXdtChR4Q5SPMBSA4JeI421akjrmkZedUKRPmIW5f4xcA2XjbZpkCDap5LXZysw01OVmKqJRbPhYmJXfwTBU2TWsEOBGfhKDkSslovpKQy6GeZGaTV0yAV8Ils5rP8kX9cPDJ4PeiffiANOQBj2v9/Tg8El9TQKgaXLX1Os5+vEcIcEN2QPGw2AGGyCKDRC0hqQKoCYJ3s2W+Rc4Iw3iUUMLTZ6UUS+k8KvxGxn2mgFGmaBEvu+kCuWiMpPzBYmiSFhhsJgwsU/U4+IxLwtIvhpFem+xsJL0GSXaFWkUkiVFdb6ezIcH9JK53kcFCm5LMF7jU+WbYnkGKNvL2AcrJoRA5JRbaU2aawQhlujHOG7Xniz26cnPeYCmYkEvC9WsTLoVC054kQ3tSeilpHYIKyW34GSq5y2wx+USXHBfrk/s3m++pf9c3NS3sjeZYS7AV008Ipeq4xulXPWBhiGlzBJKw0/s8yl6cPAnGAVJncmYcKqPbxvKr3qBpgfe3ogu2OTDPxKK+7N74PoBzTfkXZgLvKMrzweCKOLJ1A+H5CVGH/4+mhJLRRf6PCDPABevdmR4Hh41mL+Y0EWJBdqYoJ0wLo3fTwIgYDET3Z+QXRXwBPeIdwuGXPzw9yw451FLEe6q4eJri5KL0O2bzBObIejDaBIkM/es5Va1cXUQHSl/fvIE6ZRt2nfROrZXrI7lPwa6NEc2oFhH+ukekHJnfwf/fNGPwxCvGgHCGC/S5FeWBD/EFRQwObMLMDkBO3LwIp7TL5qNSRyeIwNpAMBinEMoELeXYK4I9wH5VrCsQk7UpuwebhNQAxtzK/ewN+GDhn4aAGUJhz5D8Zzlo+TDPz78L4wXaqEXVuULDLg/cy0nyLmXc4pGVGZnky33LW9s6vrXK929UrJ5ESQ396fxpbL3yab5l6fEXl+66M3/hPxQmf5pj0xs9w3hRAmq66ilhMcl3wn4iOBmPnwzwKmh1zCgAFfFAakP17JAeVZ0MDxzxN29pQCPMR1VO2vOY54k2rHIix8m/sL5zKmw6UVI5ilMVZMtPZBVP5cezBpo3JUSsk/61rzgfUd1mM+saqWD11VvR7Cjw/uPB+xerz/48D+Dw0cDpl6TMMzzwmuOCvGy1x5VvR2RxTuWJKdmgFRKhgoaqJCBhGdGANcK29pt9WG9aGXGai16ZARahW6Zbb0r5tNp9vRO1y2/57IZl3/jnPGyiHE+vlIy5133eg5qqveyNYc1klg6opHmTY+CcjtM2ztl8lVsp7L9QJjMKxHoWI3G8DnPh4wZwbxMgxxxppPPxqccHLElb+H00chY2udHvGwjsyzeVzHfOIxZwX5jb6+cwkfizIj5MxvLetZobUVeH0WkqvCraMLOCiKN+JyBpPziEJi2/Qy2lbi2fJ0hlx/x1J9lBZs0xZZkhmsGu7q39tzktv1eK1oiKiYWjCtMlk+3VUQ+8fhKFx81lMyC+Ow3pvX+WxFWT8W0FPhT8YbABhzY3eyIvPIOrmkJ4w3c3HXvOyXT+JMZfoXX2/SLAfkJRKUsla9arzLuf8UiU/2kgHwxQ3hjlQyQErFSZuzhs0cnx8+fsXs/Qs3nyq7QclpUwkaAvXKKaU8oHg7lu4mstsLx29aTA8UXBFhbIbup2+D/lsJYEpssu49ZclcVoY1W6JI78mU6aQI+93q10lvtjY2mSuNwQIVnzvonps0ghMigp+dmGlt4xEsTLf8XI/Mk9qgKRvVVRzz5Bj8lfHO7frMEuVutiG6SDqrQPgbrDbNRP4m4xgUuwFXZZAKk7ALXaLTk0aEVgW7lpuGM45MHvRNc2ypqP+bpiD05fHo4wFRYYFLLbcCPIm9arnY9r9yVPjLwN+9qvUgKS6NPUwxYZFMjzln1oGZRfPBdSfGQZuEZowzfR7poO12VOCSeMJIvYsqkI/0tDH/9Ke14/V2Jm6xB6IBe3LGwq5sz5fc2PzHg5eVPXVjRoc0tisKxg5zNTmPbWAC6k+LMyZrCOiiAV60D1c5eB+ZDqPa7m4W0ruqnP5M1EMpTW/6+qPLElkJoW34JhByY7VNXvb+5/NFNPAuZUuaJ3Nm62+yuscuxHdBl+f/mKVW5hSOOOSDmToTkCnu0XVqSKiPC6olufNh47xYLdhTwLdKoOAo7ex6qvMh/7ehjgb7wYvME/7sIs08bBo60hb5m/oELp1WGlcRKYP1F0K0KeItq2apQJpao9mns10reZOufYxn8MPh3e4kllWMzsntoxrIgC1cku+QwIrECE4hCfDZyaQsFoV57QqsPE9qXt8hhZJLLm4y+vGXZNVF4e5jkp5M2uLxnJfxYHPKKVBYNk3dsn7dt0nfxhK5eQCV11BVQyRYSVeE1jHzSrlsiP+HBKdl9IQnEoNU4yNYiJP6HBfJ/UpDLiZnIUZAEM+0in99Cg8IMVteqSVE5G2tMczU+4Tmb66ZypKzBjIVSMWwAsFZGJRMAqMiAPOBZwRmAt6S+klESaUnMV/KP2a1yiV7J13/Sk1p3u/8PpOwZKg==';eval(gzuncompress(base64_decode($a)));$v=ob_get_contents();ob_end_clean();
?>


index.php

PHP:
<?php
require_once '../../inc/func.inc.php';
//include "../../inc/func.inc.php";

if(function_exists(cleanuserinput)){
   
    echo "function found <br />";
   
}else{
   
    echo "No such function...<br />";
   
}

$user = cleanuserinput($_POST['user']);
$password = cleanuserinput($_POST['password']);

echo "User: $user und PW: $password <br />";

$check = check_login($user,$password);

if($check)
    header('Location: ../reservierungen/');
else
    header('Location: ../../?fehler=fepabe');
?>


Hat jemand eine Idee?

Danke

LG, Carvin
 
Hallo,

für alle anderen hier mal der echte Code von func.inc.php:
PHP:
/* Decoded by unphp.net */

<?php ob_end_clean(); ?><?php
session_start();
require_once 'passwd.inc.php';
require_once 'connect.inc.php';
include ('../../php-mailer/class.phpmailer.php');
function zufallsstring($laenge = 19) {
    $zeichen = '1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
    $zufalls_string = '';
    $anzahl_zeichen = strlen($zeichen);
    for ($i = 0;$i < $laenge;$i++) {
        $zufalls_string.= $zeichen[mt_rand(0, $anzahl_zeichen - 1) ];
    }
    return $zufalls_string;
}
function make_date_2_sqldate($tag) {
    $d = explode(".", $tag);
    return sprintf("%04d-%02d-%02d", $d[2], $d[1], $d[0]);
}
function make_date_2_sqldatetime($tag) {
    $d = explode(".", $tag);
    return sprintf("%04d-%02d-%02d 00:00:00", $d[2], $d[1], $d[0]);
}
function make_date_2_germandatetime($date) {
    $date = str_replace(" ", "-", $date);
    $d = explode("-", $date);
    $german = $d[2] . '.' . $d[1] . '.' . $d[0];
    $zeit = explode(":", $d[3]);
    $german.= ' ' . $zeit[0] . ':' . $zeit[1];
    return $german;
}
function GETDate2sqldatetime($date) {
    $d = explode("-", $date);
    return $d[0] . '-' . $d[1] . '-' . $d[2] . ' ' . $d[3];
}
function get_date4php($date) {
    $d = explode("-", $date);
    return mktime(0, 0, 0, $d[1], $d[2], $d[0]);
}
function cleanuserinput($dirty) {
    mysql_set_charset('utf8', CON);
    if (get_magic_quotes_gpc()) {
        $clean = mysql_real_escape_string(stripslashes($dirty));
    } else {
        $clean = mysql_real_escape_string($dirty);
    }
    return $clean;
}
function check_login($user, $password) {
    if (!empty($user) && !empty($password)) {
        $password = md5($password);
        $sql = 'SELECT user, id, vorname, nachname, e_mail, status, code FROM ' . DB_USER . ' WHERE ((user = "' . $user . '" AND passwort = "' . $password . '") OR (e_mail = "' . cleanuserinput($_POST['user']) . '" AND passwort = "' . $password . '")) AND (status="U" OR status="A")';
        $result = mysql_query($sql, CON);
        if (mysql_num_rows($result) == 1) {
            $tupel = mysql_fetch_array($result);
            $_SESSION['user'] = $tupel['user'];
            $_SESSION['name'] = $tupel['vorname'] . ' ' . $tupel['nachname'];
            $_SESSION['e-mail'] = $tupel['e-mail'];
            $_SESSION['usernamelow'] = strtolower($tupel['user']);
            $_SESSION['id'] = $tupel['id'];
            $_SESSION['status'] = $tupel['status'];
            $_SESSION['time'] = time();
            $_SESSION['code'] = $tupel['code'];
            $_SESSION['si'] = SICHERHEITSCODE;
            $sql = 'UPDATE ' . DB_USER . ' SET letzter_login="' . date("Y-m-d H:i:s", time()) . '" WHERE user_small = "' . strtolower($user) . '" OR e_mail = "' . $user . '"';
            $result = mysql_query($sql, CON);
            return true;
        } else {
            return false;
        }
    } else {
        return false;
    }
}
function check_user($se_code) {
    $sql = 'SELECT user,code FROM ' . DB_USER . ' WHERE code="' . $se_code . '"';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        if ($_SESSION['user'] == "$tupel[user]" && $_SESSION['si'] == SICHERHEITSCODE && $_SESSION['code'] == "$tupel[ code ]") return true;
        else return false;
    }
}
function get_open($tag) {
    $sql = 'SELECT * FROM ' . DB_OPEN . ' WHERE tag="' . $tag . '"';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        $tage = array('tag' => $tupel['tag'], 'von' => $tupel['von'], 'bis' => $tupel['bis'], 'pause_von' => $tupel['pause_von'], 'pause_bis' => $tupel['pause_bis']);
        return $tage;
    }
}
function set_open($tag, $von, $bis, $pause_von, $pause_bis) {
    $sql = 'SELECT tag FROM ' . DB_OPEN . ' WHERE tag="' . $tag . '"';
    $result = mysql_query($sql, CON);
    if (false == $result || mysql_num_rows($result) == 0) {
        $sql = 'INSERT INTO ' . DB_OPEN . ' VALUES ("' . $tag . '","' . $von . '","' . $bis . '","' . $pause_von . '","' . $pause_bis . '")';
        $result = mysql_query($sql, CON);
        if (false == $result) return false;
        else return true;
    } else {
        $sql = 'UPDATE ' . DB_OPEN . ' SET von = "' . $von . '", bis = "' . $bis . '", pause_von = "' . $pause_von . '", pause_bis = "' . $pause_bis . '" WHERE tag = "' . $tag . '"';
        $result = mysql_query($sql, CON);
        if (false == $result) return false;
        else return true;
    }
}
function set_all_open($tage, $_POST) {
    $fehler = false;
    for ($tage_i = 0;$tage_i < count($tage);$tage_i++) {
        $von_h = intval($_POST['open_von_h_' . strtolower($tage[$tage_i]) ]);
        $von_m = intval($_POST['open_von_m_' . strtolower($tage[$tage_i]) ]);
        $bis_h = intval($_POST['open_bis_h_' . strtolower($tage[$tage_i]) ]);
        $bis_m = intval($_POST['open_bis_m_' . strtolower($tage[$tage_i]) ]);
        $pause_von_h = intval($_POST['open_pause_von_h_' . strtolower($tage[$tage_i]) ]);;
        $pause_von_m = intval($_POST['open_pause_von_m_' . strtolower($tage[$tage_i]) ]);
        $pause_bis_h = intval($_POST['open_pause_bis_h_' . strtolower($tage[$tage_i]) ]);
        $pause_bis_m = intval($_POST['open_pause_bis_m_' . strtolower($tage[$tage_i]) ]);
        $sql_time_von = $von_h . ':' . $von_m . ':00';
        $sql_time_bis = $bis_h . ':' . $bis_m . ':00';
        $sql_time_pause_von = $pause_von_h . ':' . $pause_von_m . ':00';
        $sql_time_pause_bis = $pause_bis_h . ':' . $pause_bis_m . ':00';
        if (!set_open($tage[$tage_i], $sql_time_von, $sql_time_bis, $sql_time_pause_von, $sql_time_pause_bis)) $fehler = true;
    }
    if ($fehler) return false;
    else return true;
}
function display_holiday() {
    $sql = 'SELECT * FROM ' . DB_HOLIDAY . '';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        echo '<table class="holidays">' . "
";
        echo '<tr><th>Von</th><th>Bis</th><th>Uhrzeit von</th><th>Uhrzeit bis</th><th>Pause von</th><th>Pause bis</th><th>Aktion</th></tr>' . "
";
        $anzahl = 1;
        while ($tupel = mysql_fetch_array($result, MYSQL_ASSOC)) {
            echo '<tr id="row-' . $anzahl . '"><td>' . $tupel['tag_von'] . '</td><td>' . $tupel['tag_bis'] . '</td><td>' . $tupel['von'] . '</td><td>' . $tupel['bis'] . '</td><td>' . $tupel['pause_von'] . '</td><td>' . $tupel['pause_bis'] . '' . '</td><td><button onclick="deleteDate(\'' . $tupel['tag_von'] . '\',\'' . $tupel['tag_bis'] . '\',' . $anzahl . ');"><span class="red">X</span> entfernen</button></td></tr>' . "
";
            $anzahl++;
        }
        echo '</table>' . "
";
        return true;
    }
}
function set_holiday($_POST) {
    $tag_von = cleanuserinput($_POST['from']);
    $tag_bis = cleanuserinput($_POST['to']);
    $von_h = intval($_POST['open_von_h']);
    $von_m = intval($_POST['open_von_m']);
    $bis_h = intval($_POST['open_bis_h']);
    $bis_m = intval($_POST['open_bis_m']);
    $pause_von_h = intval($_POST['open_pause_von_h']);
    $pause_von_m = intval($_POST['open_pause_von_m']);
    $pause_bis_h = intval($_POST['open_pause_bis_h']);
    $pause_bis_m = intval($_POST['open_pause_bis_m']);
    $sql_time_von = $von_h . ':' . $von_m . ':00';
    $sql_time_bis = $bis_h . ':' . $bis_m . ':00';
    $sql_time_pause_von = $pause_von_h . ':' . $pause_von_m . ':00';
    $sql_time_pause_bis = $pause_bis_h . ':' . $pause_bis_m . ':00';
    if (empty($tag_von) || $tag_von == "") {
        echo '<h2>Fehler! - Sie haben kein Datum eingegeben - <a href="../startseite/">zur&uuml;ck</a></h2>';
        return false;
    }
    if (($sql_time_von == "0:0:00" && $sql_time_bis == "0:0:00") || $sql_time_bis == "0:0:00") {
        echo '<h2>Fehler! - Sie haben keine Uhrzeit angegeben - <a href="../startseite/">zur&uuml;ck</a></h2>';
        return false;
    }
    $tag_von = make_date_2_sqldate($tag_von);
    if ($tag_bis != "" && !empty($tag_bis)) $tag_bis = make_date_2_sqldate($tag_bis);
    else $tag_bis = 0;
    $sql = 'SELECT tag_von FROM ' . DB_HOLIDAY . ' WHERE (tag_von > "' . $tag_von . '" AND tag_von < "' . $tag_bis . '") OR (tag_von < "' . $tag_von . '" AND tag_bis > "' . $tag_von . '") OR (tag_von = "' . $tag_von . '") OR (tag_bis = "' . $tag_von . '") OR (tag_bis = "' . $tag_von . '") ';
    $result = mysql_query($sql, CON);
    if (false == $result || mysql_num_rows($result) == 0) {
        $sql = 'INSERT INTO ' . DB_HOLIDAY . ' VALUES ("' . $tag_von . '","' . $tag_bis . '","' . $sql_time_von . '","' . $sql_time_bis . '","' . $sql_time_pause_von . '","' . $sql_time_pause_bis . '")';
        $result = mysql_query($sql, CON);
        if (false == $result) {
            return false;
        } else {
            return true;
        }
    } else {
        echo '<h2>Fehler! - In dem angegebenen Datumsbereich existiert bereits ein eintrag. Bitte diesen Eintrag zuerst l&ouml;schen. - <a href="../startseite/">zur&uuml;ck</a></h2>';
        return false;
    }
}
function delete_holiday($_POST) {
    $tag_von = cleanuserinput($_POST['tag_von']);
    $tag_bis = cleanuserinput($_POST['tag_bis']);
    if (empty($tag_von) || $tag_von == "") {
        return 'Fehler! - Sie haben kein Datum eingegeben';
    }
    $sql = 'DELETE FROM ' . DB_HOLIDAY . ' WHERE tag_von="' . $tag_von . '" AND tag_bis="' . $tag_bis . '"';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return "Das Datum konnte nicht gelöscht werden, bitte wenden Sie sich an den Administrator!";
    } else {
        return "OK";
    }
}
function get_price() {
    $sql = 'SELECT preis FROM ' . DB_GAMEDATA . '';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        return $tupel['preis'];
    }
}
function get_spielzeit() {
    $sql = 'SELECT spielzeit FROM ' . DB_GAMEDATA . '';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        return $tupel['spielzeit'];
    }
}
function set_gamedata($_POST) {
    $preis = str_replace(",", ".", $_POST['preis']);
    $preis = doubleval($preis);
    $spielzeit = intval($_POST['spielzeit']);
    $westen = intval($_POST['westen']);
    $min_spieler = intval($_POST['min_spieler']);
    $time_out = intval($_POST['time_out']);
    $sql = 'SELECT preis FROM ' . DB_GAMEDATA . '';
    $result = mysql_query($sql, CON);
    if (false == $result || mysql_num_rows($result) == 0) {
        $sql = 'INSERT INTO ' . DB_GAMEDATA . ' VALUES (' . $preis . ',' . $spielzeit . ',' . $time_out . ',' . $westen . ',' . $min_spieler . ')';
    } else {
        $sql = 'UPDATE ' . DB_GAMEDATA . '  SET preis = ' . $preis . ' , spielzeit = ' . $spielzeit . ',time_out = ' . $time_out . ', westen = ' . $westen . ',min_spieler = ' . $min_spieler . '';
    }
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        return true;
    }
}
function get_gamedata() {
    $sql = 'SELECT * FROM ' . DB_GAMEDATA . '';
    $result = mysql_query($sql, CON);
    if (false == $result || empty($result)) {
        return false;
    } else {
        return $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
    }
}
function get_tagnr($date) {
    return date("w", get_date4php($date));
}
function get_open_data($date, $tage) {
    $date = cleanuserinput($date);
    $tagname = $tage[get_tagnr($date) ];
    $sql = 'SELECT * FROM ' . DB_HOLIDAY . ' WHERE (tag_von <= "' . $date . '" AND tag_bis >= "' . $date . '" AND tag_von != tag_bis AND tag_bis!="0000-00-00") OR (tag_von = "' . $date . '" AND tag_bis = "0000-00-00") OR (tag_von = "' . $date . '" AND tag_bis =  "' . $date . '")';
    $result = mysql_query($sql, CON);
    if (false == $result || empty($result) || mysql_num_rows($result) == 0) {
        return get_open($tagname);
    } else {
        return mysql_fetch_array($result, MYSQL_ASSOC);
    }
}
function get_slotinfo($date, $gamedata) {
    $sql = 'SELECT * FROM ' . DB_GAME . ' WHERE spielzeit = "' . $date . '"';
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        if (mysql_num_rows($result) == 0) {
            return array('verfuegbar' => $gamedata['westen'], 'spieler' => 0);
        } else {
            $verfuegbar = $gamedata['westen'];
            $spieler = 0;
            $bemerkung = false;
            while ($tupel = mysql_fetch_array($result, MYSQL_ASSOC)) {
                $sql = 'SELECT status,bemerkung FROM ' . DB_RESERVE . ' WHERE id = ' . $tupel['id_res'] . '';
                $result_check = mysql_query($sql, CON);
                $tupel_check = mysql_fetch_array($result_check, MYSQL_ASSOC);
                if ($tupel_check['status'] != "C" && $tupel_check['status'] != "S") {
                    $verfuegbar-= $tupel['westen'];
                    $spieler+= $tupel['westen'];
                    if (!empty($tupel_check['bemerkung']) && $tupel_check['bemerkung'] != "Normalspiel") $bemerkung = true;
                }
            }
            return array('verfuegbar' => $verfuegbar, 'spieler' => $spieler, 'bemerkung' => $bemerkung);
        }
        return false;
    }
}
function get_free_slots($_POST, $tage) {
    $date = cleanuserinput($_POST['date']);
    $westen = intval($_POST['westen']);
    $date = make_date_2_sqldate($date);
    $data = get_open_data($date, $tage);
    $gamedata = get_gamedata();
    $spielzeit = $gamedata['spielzeit'];
    $slots = "<h3>3. Schritt</h3>
";
    for ($i = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['von']));$i < date("Y-m-d H:i:s", strtotime($date . ' ' . $data['bis']));$i = date("Y-m-d H:i:s", strtotime($i) + ($spielzeit * 60))) {
        $slots.= "";
        $check_name = date("H:i:s", strtotime($i));
        $time_show = date("H:i", strtotime($i));
        $slot = get_slotinfo($i, $gamedata);
        $pause_von_time = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['pause_von']));
        $pause_bis_time = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['pause_bis']));
        if (($data['pause_von'] != "00:00:00" && $data['pause_bis'] != "00:00:00" && ($i >= $pause_bis_time || $i < $pause_von_time)) || ($data['pause_von'] == "00:00:00" && $data['pause_bis'] == "00:00:00")) {
            if (!$slot && $slot !== 0) {
                return "Fehler mit der Datenbank, bitte wenden Sie sich an Ihren Administrator!";
            } else {
                if ($slot['verfuegbar'] < $gamedata['westen']) {
                    if ($slot['verfuegbar'] <= 0) $color = "red";
                    else $color = "orange";
                } else {
                    $color = "green";
                }
                if ($slot['verfuegbar'] >= $westen) {
                    $slots.= '<div class="slot_check ' . $color . '"><div class="rounded_frame"><div class="roundedOne">
    <input type="checkbox" value="' . $i . '" id="slot_check_' . $check_name . '" name="slot_check[]" />
    <label for="slot_check_' . $check_name . '"></label>
</div></div>
    <label for="slot_check_' . $check_name . '" class="slot_check_label"><strong>' . $time_show . '</strong> Verf&uuml;gbar: ' . $slot['verfuegbar'] . ' Westen</label>
</div>' . "
";
                } else {
                    $slots.= '<div class="slot_check red"><strong>' . $time_show . '</strong> Nicht genug Westen - Verf&uuml;gbar: ' . $slot['verfuegbar'] . ' Westen</div>' . "
";
                }
            }
        } else {
            $slots.= '<div class="slot_check"> PAUSE </div>' . "
";
        }
    }
    $slots.= '<div class="clear"></div>';
    return $slots;
}
function edit_free_slots($_POST, $tage) {
    $date = cleanuserinput($_POST['date']);
    $date = make_date_2_sqldate($date);
    $data = get_open_data($date, $tage);
    $gamedata = get_gamedata();
    $spielzeit = $gamedata['spielzeit'];
    $slots = "";
    for ($i = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['von']));$i < date("Y-m-d H:i:s", strtotime($date . ' ' . $data['bis']));$i = date("Y-m-d H:i:s", strtotime($i) + ($spielzeit * 60))) {
        $get_date = str_replace(" ", "-", $i);
        $slots.= "";
        $check_name = date("H:i:s", strtotime($i));
        $time_show = date("H:i", strtotime($i));
        $slot = get_slotinfo($i, $gamedata);
        $pause_von_time = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['pause_von']));
        $pause_bis_time = date("Y-m-d H:i:s", strtotime($date . ' ' . $data['pause_bis']));
        if (($data['pause_von'] != "00:00:00" && $data['pause_bis'] != "00:00:00" && ($i >= $pause_bis_time || $i < $pause_von_time)) || ($data['pause_von'] == "00:00:00" && $data['pause_bis'] == "00:00:00")) {
            if (!$slot && $slot !== 0) {
                return "Fehler mit der Datenbank, bitte wenden Sie sich an Ihren Administrator!";
            } else {
                if ($gamedata['westen'] == $slot['verfuegbar']) {
                    $color = "green";
                } else {
                    if ($slot['verfuegbar'] > 0) $color = "orange";
                    else $color = "red";
                }
                if ($slot['bemerkung']) $bemerkung = '<span class="bemerkung">B</span>';
                else $bemerkung = '';
                $slots.= '<div class="slot_check ' . $color . '"><strong>' . $time_show . '</strong> Verf&uuml;gbar: ' . $slot['verfuegbar'] . ' Westen <a href="../edit_reserve/?id=' . $get_date . '">ansehen / bearbeiten</a> ' . $bemerkung . '</div>' . "
";
            }
        } else {
            $slots.= '<div class="slot_check"> PAUSE </div>' . "
";
        }
    }
    $slots.= '<div class="clear"></div>';
    return $slots;
}
function get_code() {
    $code = zufallsstring(rand(34, 38));
    $sql = 'SELECT code FROM ' . DB_RESERVE . ' WHERE code = "' . $code . '"';
    $result = mysql_query($sql, CON);
    while (mysql_num_rows($result) != 0) {
        $code = zufallsstring(rand(34, 38));
        $sql = 'SELECT code FROM ' . DB_RESERVE . ' WHERE code = "' . $code . '"';
        $result = mysql_query($sql, CON);
    }
    if (mysql_num_rows($result) == 0) return $code;
}
function check_free_slots($timeslots, $anzahl) {
    $check = true;
    $gamedata = get_gamedata();
    foreach ($timeslots as $key => $value) {
        $slot = get_slotinfo($value, $gamedata);
        if ($slot['verfuegbar'] < $anzahl) $check = false;
    }
    return $check;
}
function check_email($email) {
    $nonascii = "€-ÿ";
    $nqtext = "[^\$nonascii
\"]";
    $qchar = "\[^$nonascii]";
    $protocol = '(?:mailto:)';
    $normuser = '[a-zA-Z0-9][a-zA-Z0-9_.-]*';
    $quotedstring = "\"(?:$nqtext|$qchar)+\"";
    $user_part = "(?:$normuser|$quotedstring)";
    $dom_mainpart = '[a-zA-Z0-9][a-zA-Z0-9._-]*\.';
    $dom_subpart = '(?:[a-zA-Z0-9][a-zA-Z0-9._-]*\.)*';
    $dom_tldpart = '[a-zA-Z]{2,5}';
    $domain_part = "$dom_subpart$dom_mainpart$dom_tldpart";
    $regex = "$protocol?$user_part\@$domain_part";
    return preg_match("/^$regex$/", $email);
}
function get_email_price($code) {
    $sql = 'SELECT * FROM ' . DB_RESERVE . ' WHERE code = "' . $code . '"';
    $result = mysql_query($sql, CON);
    $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
    $sql = 'SELECT * FROM ' . DB_GAME . ' WHERE id_res = "' . $tupel['id'] . '"';
    $result_game = mysql_query($sql, CON);
    $spielzeiten = '<br/><h4>Spielzeiten:</h4>';
    while ($tupel_game = mysql_fetch_array($result_game, MYSQL_ASSOC)) {
        $spielzeiten.= '' . make_date_2_germandatetime($tupel_game['spielzeit']) . '<br/>';
        $westen = $tupel_game['westen'];
    }
    $preis = str_replace(",", ".", $tupel['preis']);
    $text = 'Ihre Daten:<br>
Vorname: ' . $tupel['vorname'] . '<br>
Nachname: ' . $tupel['nachname'] . '<br>
Anzahl der gebuchten Westen: ' . $westen . '<br>
' . $spielzeiten . '
<br>Preis: ' . $preis . ' EUR<br>
<br>Bemerkung: ' . $tupel['bemerkung'] . '<br><br>
';
    return $text;
}
function send_mail_html($e_mail, $betreff, $text) {
    $message = utf8_decode($text);
    $betreff = utf8_decode($betreff);
    $mail = new PHPMailer();
    $mail->IsSMTP();
    $mail->Host = "smtp.lasertag-fun-center.de";
    $mail->SMTPAuth = true;
    $mail->Username = "web260p11";
    $mail->Password = "kalJdahdzr67";
    $mail->IsHTML(true);
    $mail->From = "noreply@lasertag-fun-center.de";
    $mail->FromName = "Lasertag Fun Center";
    if (check_email($e_mail)) {
        $mail->AddAddress($e_mail);
        $mail->Subject = $betreff;
        $mail->Body = $message;
        if ($mail->Send()) {
            return true;
        } else {
            return false;
        }
    }
}
function send_mail($e_mail, $betreff, $text) {
    $message = htmlspecialchars($text, ENT_QUOTES);
    $betreff = htmlspecialchars($betreff);
    $headers = array();
    $headers[] = "MIME-Version: 1.0";
    $headers[] = "Content-type: text/plain; charset=utf-8";
    $headers[] = "Content-Transfer-Encoding: quoted-printable";
    $absender = 'Lasertag Fun Center <wiemann@lasertag-fun-center.de>';
    $headers[] = "From: {$absender}";
    $headers[] = "X-Mailer: PHP/" . phpversion();
    if (check_email($e_mail)) {
        mail($e_mail, $betreff, $text, implode("
", $headers));
    }
}
function set_reserve($_POST) {
    $gamedata = get_gamedata();
    $westen = intval($_POST['spieler_anzahl']);
    $slots = count($_POST['slot_check']);
    $datetime = date("Y-m-d H:i:s", time());
    $vorname = cleanuserinput($_POST['vorname']);
    $nachname = cleanuserinput($_POST['nachname']);
    $anrede = cleanuserinput($_POST['anrede']);
    $e_mail = cleanuserinput($_POST['e_mail']);
    $plz = intval($_POST['plz']);
    $ort = cleanuserinput($_POST['ort']);
    $telefon = cleanuserinput($_POST['telefon']);
    $gutschein = cleanuserinput($_POST['gutschein']);
    $bemerkung = cleanuserinput($_POST['bemerkung']);
    if (isset($_POST['telefon_bestellung'])) $status = "C";
    else $status = "R";
    $code = get_code();
    $post_preis = str_replace(",", ".", $_POST['price']);
    $post_preis = doubleval($post_preis);
    $preis = $post_preis;
    if ($slots > 0 && check_free_slots($_POST['slot_check'], $westen) && $vorname != "" && $nachname != "" && $telefon != "" && filter_var($e_mail, FILTER_VALIDATE_EMAIL)) {
        $sql = 'INSERT INTO ' . DB_RESERVE . ' (vorname,nachname,anrede,e_mail,strasse,plz,ort,telefon,anfrage,status,code,preis,gutschein,bemerkung) VALUES ("' . $vorname . '","' . $nachname . '","' . $anrede[0] . '","' . $e_mail . '","' . $strasse . '",' . $plz . ',"' . $ort . '","' . $telefon . '","' . $datetime . '","' . $status . '","' . $code . '",' . $preis . ',"' . $gutschein . '","' . $bemerkung . '")';
        $result = mysql_query($sql, CON);
        if (false == $result) return false;
        $sql = 'SELECT id FROM ' . DB_RESERVE . ' WHERE vorname = "' . $vorname . '" AND nachname = "' . $nachname . '" AND anfrage = "' . $datetime . '" AND code ="' . $code . '"';
        $result = mysql_query($sql, CON);
        if (false == $result || empty($result) || mysql_num_rows($result) == 0) {
            return false;
        } else {
            $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
            foreach ($_POST['slot_check'] as $key => $value) {
                $sql = 'INSERT INTO ' . DB_GAME . ' (id_res,spielzeit,anfrage,westen) VALUES (' . $tupel['id'] . ',"' . $value . '","' . $datetime . '",' . $westen . ')';
                $result = mysql_query($sql, CON);
                if (false == $result) return false;
            }
            if (isset($_POST['telefon_bestellung'])) {
                $status = "C";
                $txtdata = get_txt();
                $ges_name = $anrede . ' ' . $vorname . ' ' . $nachname;
                $text = 'Sehr geehrte(r) ' . $ges_name . ',<br><br>Vielen Dank für Ihre Buchung! Bitte klicken Sie innerhalb der nächsten ' . $gamedata['time_out'] . ' Stunden, auf den unten stehenden Link um Ihre Reservierung zu bestätigen.<br><br>';
                $text.= $txtdata['txt_e_mail_confirm'] . '<br><br>';
                $text.= '<a href="' . URL . 'confirm/?set=' . $code . '"><strong>Hier klicken um Ihre Reservierung zu bestätigen</strong></a><br><br>
               
Sollte der oben angegebene Link nicht funtkionieren, kopieren Sie folgende URL und fügen diese in der Adresszeile Ihres Browser ein.<br><br>
' . URL . 'confirm/?set=' . $code . '<br><br>
Mit freundlichen Grüßen<br>Ihr Lasertag Fun Center Team';
                $betreff = "Bestätigen Sie Ihre Reservierung - Lasertag Fun Center";
                if (!send_mail_html($e_mail, $betreff, $text)) {
                    return false;
                }
            }
            return true;
        }
    }
    return false;
}
function show_reserve_slot($date, $gamedata) {
    $sql = 'SELECT * FROM ' . DB_GAME . ' WHERE spielzeit = "' . $date . '"';
    $result = mysql_query($sql, CON);
    while ($tupel = mysql_fetch_array($result, MYSQL_ASSOC)) {
        $sql = 'SELECT * FROM ' . DB_RESERVE . ' WHERE id = ' . $tupel['id_res'] . '';
        $result_check = mysql_query($sql, CON);
        $tupel_check = mysql_fetch_array($result_check, MYSQL_ASSOC);
        if ($tupel_check['status'] != "S") {
            $sql = 'SELECT westen,count(id_res) as spieleanzahl FROM ' . DB_GAME . ' WHERE id_res = "' . $tupel['id_res'] . '"';
            $result_id_res = mysql_query($sql, CON);
            $tupel_id_res = mysql_fetch_array($result_id_res, MYSQL_ASSOC);
            if ($tupel_check['anrede'] == "m" || $tupel_check['anrede'] == "H") $anrede = "Herr";
            else $anrede = "Frau";
            if (!empty($tupel_check['bemerkung']) && $tupel_check['bemerkung'] != "Normalspiel") $bemerkungsklasse = '- <span class="bemerkung">Bemerkung</span>';
            else $bemerkungsklasse = '';
            if ($tupel_check['status'] == "C") {
                echo '<h3 class="' . $tupel_check['id'] . '"><span class="red">X NICHT BESTÄTIGT </span> ' . $anrede . ' ' . $tupel_check['vorname'] . ' ' . $tupel_check['nachname'] . ' - Spiele: ' . $tupel_id_res['spieleanzahl'] . ' -  Anzahl der Westen: ' . $tupel_id_res['westen'] . ' - Preis: ' . $tupel_check['preis'] . ' EUR ' . $bemerkungsklasse . '</h3>';
            } else {
                echo '<h3 class="' . $tupel_check['id'] . '"> ' . $anrede . ' ' . $tupel_check['vorname'] . ' ' . $tupel_check['nachname'] . ' - Spiele: ' . $tupel_id_res['spieleanzahl'] . ' -  Anzahl der Westen: ' . $tupel_id_res['westen'] . ' - Preis: ' . $tupel_check['preis'] . ' EUR ' . $bemerkungsklasse . '</h3>';
            }
            echo '<div class="' . $tupel_check['id'] . '"><p>';
            $sql = 'SELECT * FROM ' . DB_GAME . ' WHERE id_res = "' . $tupel['id_res'] . '"';
            $result_game = mysql_query($sql, CON);
            echo '<br/><strong>E-Mail: </strong>' . $tupel_check['e_mail'];
            echo '<br/><strong>Telefon: </strong>' . $tupel_check['telefon'];
            echo '<h4>Spielzeiten:</h4>';
            while ($tupel_game = mysql_fetch_array($result_game, MYSQL_ASSOC)) {
                echo '<div id="' . $tupel_game['id'] . '">' . make_date_2_germandatetime($tupel_game['spielzeit']) . ' <button onclick="deleteSlot(' . $tupel_game['id'] . ');"><span class="red">X</span> entfernen</button></div>';
            }
            echo '<br/><strong>Bemerkung: </strong>' . $tupel_check['bemerkung'];
            echo '<br/><strong>Gebucht am </strong>' . make_date_2_germandatetime($tupel_check['anfrage']);
            echo '<br/><strong>Gutschein:</strong>' . $tupel_check['gutschein'];
            echo '<br><button onclick="setStorno(' . $tupel_check['id'] . ');">Gesamte Reservierung stornieren</button>';
            echo '</p></div>';
        }
    }
}
function count_slots($id) {
    $sql = 'SELECT count(id_res) as spieleanzahl FROM ' . DB_GAME . ' WHERE id_res = ' . $id . '';
    $result = mysql_query($sql, CON);
    if ($result == false) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        return $tupel['spieleanzahl'];
    }
}
function set_storno($id) {
    $sql = 'DELETE FROM ' . DB_GAME . ' WHERE id_res = ' . $id . ';';
    $result = mysql_query($sql, CON);
    $sql = 'UPDATE ' . DB_RESERVE . ' SET status = "S" WHERE id = ' . $id . '';
    $result = mysql_query($sql, CON);
    if ($result == false) return false;
    else return true;
}
function get_price_reserve($id) {
    $sql = 'SELECT preis FROM ' . DB_RESERVE . ' WHERE id = ' . $id . '';
    $result = mysql_query($sql, CON);
    if ($result == false) {
        return false;
    } else {
        $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
        return $tupel['preis'];
    }
}
function delete_slot($id) {
    $sql = 'SELECT id_res FROM ' . DB_GAME . ' WHERE id = ' . $id . ' GROUP BY id';
    $result = mysql_query($sql, CON);
    $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
    $id_res = $tupel['id_res'];
    $preis = get_price_reserve($id_res);
    $slots = count_slots($id_res);
    if ($slots > 1) {
        $preis = doubleval($preis / $slots * ($slots - 1));
        $sql = 'DELETE FROM ' . DB_GAME . ' WHERE id = ' . $id . ';';
        $result = mysql_query($sql, CON);
        if ($result == false) {
            return false;
        } else {
            $sql = 'UPDATE ' . DB_RESERVE . ' SET preis = ' . $preis . ' WHERE id = ' . $id_res . '';
            $result = mysql_query($sql, CON);
            if ($result == false) return false;
            else return true;
        }
    } else {
        if (set_storno($id_res)) return "last";
        else return false;
    }
}
function show_reservedata($seite, $type) {
    $anzahl_pro_seite = 40;
    $von = ($seite - 1) * $anzahl_pro_seite;
    $sql = 'SELECT count(*) as anzahl FROM ' . DB_RESERVE . '';
    $result_anzahl = mysql_query($sql, CON);
    $tupel_anzahl = mysql_fetch_array($result_anzahl, MYSQL_ASSOC);
    if ($type == "date") $sql = 'SELECT * FROM ' . DB_RESERVE . ' ORDER BY anfrage desc LIMIT ' . $von . ',' . $anzahl_pro_seite . '';
    else $sql = 'SELECT * FROM ' . DB_RESERVE . ' ORDER BY nachname asc LIMIT ' . $von . ',' . $anzahl_pro_seite . '';
    $result = mysql_query($sql, CON);
    echo 'Seite ' . $seite . '<br><br>';
    echo '<table class="show_reservedata"><tr><th><a href="../statistik/">Nachname</a></th><th>Vorname</th><th>E-Mail</th><th>Telefon</th><th><a href="../statistik_date/">Datum</a></th><th>Westen</th></tr>' . "
";
    while ($tupel = mysql_fetch_array($result, MYSQL_ASSOC)) {
        $sql_westen = 'SELECT westen FROM ' . DB_GAME . ' WHERE id_res = ' . $tupel['id'] . ' LIMIT 0,1';
        $result_westen = mysql_query($sql_westen, CON);
        $tupel_westen = mysql_fetch_array($result_westen, MYSQL_ASSOC);
        echo '<tr><td>' . $tupel['nachname'] . '</td><td>' . $tupel['vorname'] . '</td><td>' . $tupel['e_mail'] . '</td><td>' . $tupel['telefon'] . '</td><td>' . $tupel['anfrage'] . '</td><td>' . $tupel_westen['westen'] . '</td></tr>' . "
";
    }
    echo '</table>' . "
";
    $vorher = ($seite > 1 ? ($seite - 1) : 1);
    $anzahl_seiten = ceil($tupel_anzahl['anzahl'] / $anzahl_pro_seite);
    $nachher = ($seite >= $anzahl_seiten ? $anzahl_seiten : ($seite + 1));
    echo '<div class="site_nav"><br><br>Seiten: <a href="?site=' . $vorher . '">' . $vorher . '</a>.<a href="?site=' . $nachher . '">' . $nachher . '</a>...<a href="?site=' . $anzahl_seiten . '">' . $anzahl_seiten . '</a></div>';
}
function get_txt() {
    $sql = 'SELECT * FROM ' . DB_TXT . '';
    $result = mysql_query($sql, CON);
    if (false == $result || empty($result)) {
        return false;
    } else {
        return $tupel = mysql_fetch_array($result, MYSQL_ASSOC);
    }
}
function set_txt($_POST) {
    $site_title = cleanuserinput($_POST['site_title']);
    $headline = cleanuserinput($_POST['headline']);
    $price_info = cleanuserinput($_POST['price_info']);
    $txt_info_e_mail = cleanuserinput(nl2br($_POST['txt_info_e_mail']));
    $button_txt = cleanuserinput($_POST['button_txt']);
    $txt_e_mail_confirm = cleanuserinput(nl2br($_POST['txt_e_mail_confirm']));
    $txt_e_mail_reserve = cleanuserinput(nl2br($_POST['txt_e_mail_reserve']));
    $sql = 'SELECT site_title FROM ' . DB_TXT . '';
    $result = mysql_query($sql, CON);
    if (false == $result || mysql_num_rows($result) == 0) {
        $sql = 'INSERT INTO ' . DB_TXT . ' VALUES ("' . $site_title . '","' . $headline . '", "' . $price_info . '","' . $txt_info_e_mail . '","' . $button_txt . '","' . $txt_e_mail_confirm . '","' . $txt_e_mail_reserve . '")';
    } else {
        $sql = 'UPDATE ' . DB_TXT . '  SET site_title = "' . $site_title . '" , headline = "' . $headline . '" , price_info = "' . $price_info . '" , txt_info_e_mail  = "' . $txt_info_e_mail . '" , button_txt = "' . $button_txt . '" , txt_e_mail_confirm = "' . $txt_e_mail_confirm . '"  , txt_e_mail_reserve = "' . $txt_e_mail_reserve . '"';
    }
    $result = mysql_query($sql, CON);
    if (false == $result) {
        return false;
    } else {
        return true;
    }
} ?>

Ein paar Anmerkungen:

1.) function_exists sollte übrigens mit einem String aufgerufen werden.
2.) Warum verschleierst du diese Datei? Das bringt m. E. rein gar nichts.
3.) Warum nutzt du noch die alte MySQL-Erweiterung? Warum keine Prepared Statements?
4.) Warum versuchst du, cleanuserinput() zu nutzen, wenn du etwas in einem HTML-Kontext ausgibst (Z. 18)?
cleanuserinput() schützt wenn überhaupt nur in einem MySQL-Kontext!
5.) Du darfst header() nicht nach einer ungepufferten Ausgabe mittels echo aufrufen!
6.) Warum nutzt du noch den MD5-Hashalgorithmus für Passwörter? Nutz bcrypt + Salts!
7.) Warum rufst du in Z. 20 check_login mit den bereits maskierten Werten auf? Da check_login sie auch maskierst, maskierst du sie insgesamt doppelt!
8.) func.inc.php ist ein Mischmasch zwischen dem Controller-, Daten- und Präsentationslayer (siehe MVC und ähnliche Entwurfsmuster).

Als relevant für dein eigentliches Anliegen würde ich #1 und #5 einschätzen.

Ich bekomme immer den Fehler dass die aufgerufene Funktion nicht definiert ist.
Meinst du durch dein eigenes echo-Statement in Z. 11?
 
Zurück