-
Notifications
You must be signed in to change notification settings - Fork 4
/
change-email.jsp
49 lines (39 loc) · 1.46 KB
/
change-email.jsp
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
<%@ include file="/header.jsp" %>
<%@page import="java.sql.Connection"%>
<%@page import="java.sql.Statement"%>
<%@page import="java.sql.SQLException"%>
<%@page import="java.sql.ResultSetMetaData"%>
<%@page import="java.sql.ResultSet"%>
<%@ page import="java.util.*,java.io.*"%>
<%@ page import="org.cysecurity.cspf.jvl.model.DBConnect"%>
<%
if(session.getAttribute("isLoggedIn")!=null)
{
%>
Enter the New Email:<br/><br/>
<form action="change-email.jsp" method="POST">
New Email ID: <input type="text" name="email" value=""/>
<input type="hidden" name="id" value="<% out.print(session.getAttribute("userid"));%>"/>
<br/><br/><input type="submit" name="change" value="Change"/>
</form>
<br/>
<%
Connection con=new DBConnect().connect(getServletContext().getRealPath("/WEB-INF/config.properties"));
String email=request.getParameter("email");
String id=request.getParameter("id");
if(email!=null && !email.equals("") && id!=null)
{
Statement stmt = con.createStatement();
stmt.executeUpdate("Update users set email='"+email+"' where id="+id);
out.print("<b class='success'>email Changed</b>");
}
out.print("<br/><br/><a href='"+path+"/myprofile.jsp?id="+session.getAttribute("userid")+"'>Return to Profile Page >></a>");
}
else
{
out.print("Please login to see Your Profile");
}
%>
<!-- CSRF -->
<!-- Insecure Direct Object Reference 2 -->
<%@ include file="/footer.jsp" %>