الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

سؤال للمختصين في امن ال Php 2

بدأه khaled338 في 25 ديسمبر 2008 · 0 رد · 308 مشاهدة · في منتدى تطوير المواقع بـ PHP
مشاركة: واتساب X فيسبوك تيليجرام
#1

418.gif

مشروع انشاء مكتبه مركزيه للحاسب الالى وهذا مشروع التخرج

المطلوب ايجاد الثغرات وتصحيحها لامن الموقع لمنع الهاكرز من وجود الثغره

ارجو منكم المساعده في هذا الكود

index

<?php

session_start() ;

// النجوم

function do_stars($lstr) {

$stars = "" ;

for($i=$lstr+1;$i<=5;$i++) {

$stars .= '<img src="images/staroff.gif">';

}

for($i=1;$i<=$lstr;$i++) {

$stars .= '<img src="images/staron.gif">';

}

return $stars;

}

//-------------------------

include_once('conect.php') ;

$action = $_GET["action"] ;

//================================================== ================================

// new regstration ------------>

//================================================== ================================

if ($action == "newreg") {

$page_title ="تسجيل مستخدم جديد";

$content = '<form action="?action=adduser" method="post" enctype="application/x-www-form-urlencoded" dir="rtl" style="margin:0">

<table>

<tr><td><label style="width:100">اسم المستخدم : <label></td><td><input type="text" name="txtusername" style="width:200"></td></tr>

<tr><td><label style="width:100">كلمة المرور : <label></td><td><input type="password" name="txtpassword" style="width:200"></td></tr>

<tr><td><label style="width:100">تأكيد كلمة المرور : <label></td><td><input type="password" name="txtpassword2" style="width:200"></td></tr>

<tr><td><input type="submit" value="تسجيل"></td></tr>

</table>

</form>' ;

}

//-----------------------------------------------------

if ($action == "adduser") {

$page_title ="تسجيل مستخدم جديد";

$user_name = $_POST["txtusername"] ;

$pass1 = $_POST["txtpassword"] ;

$pass2 = $_POST["txtpassword2"] ;

if (($pass1 == $pass2) && $user_name && $pass1) {

$res = mysql_query("SELECT fusername FROM tblusers WHERE fusername = '$user_name'");

if ($res) {

if (mysql_num_rows($res)>0) {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">اسم المستخدم موجود مسبقا</font></b>';

$content .= '<br/><a href="?action=newreg">العودة</a>';

} else {

mysql_query("INSERT INTO tblusers (fusername , fpassword) VALUES ('$user_name',MD5('$pass1'))") ;

$content = '<b><font face="Tahoma" size="2" color="#008000">تم تسجيل المستخدم بنجاح</font></b>';

$content .= '<br/><a href="?action=newreg">العودة</a>';

}

}

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">اسم مستخدم غير صحيح أو كلمة المرور غير متطابقة</font></b>';

$content .= '<br/><a href="?action=newreg">العودة</a>';

}

}

//================================================== ================================

// new regstration <------------

//================================================== ================================

//================================================== ================================

// Login ------------>

//================================================== ================================

if ($action=="login") {

if ($_POST["form"]) {

$user_name = $_POST["txtusername"] ;

$pass = $_POST["txtpassword"] ;

if ($pass && $user_name) {

$res = mysql_query("SELECT fusername FROM tblusers WHERE fusername = '$user_name' AND fpassword = MD5('$pass')");

if ($res) {

if (mysql_num_rows($res)>0) {

$content = '<b><font face="Tahoma" size="2" color="#008000">' . 'مرحبا بك ' . $user_name . ' تم تسجيل دخولك بنجاح ' . '</font></b>';

$_SESSION["islogin"] = "yes" ;

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">تسجيل دخول خاظئ</font></b>';

$content .= '<br/><a href="?action=login">العودة</a>';

unset($_SESSION["islogin"]) ;

}

}

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">تسجيل دخول خاظئ</font></b>';

$content .= '<br/><a href="?action=login">العودة</a>';

unset($_SESSION["islogin"]) ;

}

} else {

$page_title ="تسجيل الدخول";

$content = '<form action="?action=login" method="post" enctype="application/x-www-form-urlencoded" dir="rtl" style="margin:0">

<input name ="form" type="hidden" value="1">

<table>

<tr><td><label style="width:100">اسم المستخدم : <label></td><td><input type="text" name="txtusername" style="width:200"></td></tr>

<tr><td><label style="width:100">كلمة المرور : <label></td><td><input type="password" name="txtpassword" style="width:200"></td></tr>

<tr><td><input type="submit" value="تسجيل الدخول"></td></tr>

</table>

</form>' ;

}

}

//================================================== ================================

// Login ------------>

//================================================== ================================

//================================================== ================================

// BROWS CATG ------------>

//================================================== ================================

if ($action=="g") {

if ($_SESSION["islogin"]=="yes") {

$ladd = $_GET["add"] ;

$lform = $_GET["form"] ;

if (!$ladd && !$lform) {

$page_title = "إستعراض مجموعات الكتب" ;

$content = '<ul>' ;

$res = mysql_query("SELECT * FROM tblg") ;

if ($res) {

while($lROW = mysql_fetch_assoc($res)) {

$content .= '<li><a href="?action=openg&lgroub=' . $lROW["fid"] . '">' . $lROW["fname"] . '</a></li>';

}

}

$content .= '</ul>';

$content .= '<br/><a href="?action=g&add=1">إضافة مجموعة</a>';

}

if ($ladd) {

$page_title = "إضافة مجموعة جديدة" ;

$content = '<form action="?action=g&form=1" method="post" enctype="application/x-www-form-urlencoded" dir="rtl" style="margin:0">

<table>

<tr><td><label style="width:100"> اسم المجموعة<label></td><td><input type="text" name="txtg" style="width:200"></td></tr>

<tr><td><input type="submit" value="إضافة مجموعة"></td></tr>

</table>

</form>' ;

}

if ($lform) {

$page_title = "إضافة مجموعة جديدة" ;

if ($_POST["txtg"]) {

mysql_query("INSERT INTO tblg (fname) VALUES ('{$_POST["txtg"]}')") ;

$content = '<b><font face="Tahoma" size="2" color="#008000">تم إضافة المجموعة بنجاح</font></b>';

$content .= '<br/><a href="?action=g&add=1">إضافة مجموعة جديدة</a>';

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">لايمكن الحفظ بسبب نقص البيانات</font></b>';

$content .= '<br/><a href="?action=g">العودة</a>';

}

}

//================================================== ===

} else {

$page_title = "رسالة إدارية" ;

$content = '<b><font face="Tahoma" size="2" color="#FF0000">وصول غير مصرح يتوجب عليك التسجيل</font></b>';

}

}

//================================================== ================================

// BROWS CATG <------------

//================================================== ================================

//================================================== ================================

// BROWS books ------------>

//================================================== ================================

if ($action=="openg") {

if ($_SESSION["islogin"]=="yes") {

$ladd = $_GET["add"] ;

$lform = $_GET["form"] ;

$lgroub = $_GET["lgroub"] ;

$page = $_GET["page"];

if (!$page) $page= 0;

// جلب اسم المجموعة

$lxres = mysql_query("SELECT fname FROM tblg WHERE fid=$lgroub") ;

$lr = mysql_fetch_assoc($lxres) ;

$_curg = $lr["fname"];

//--------------------------

if (!$ladd && !$lform) {

$page_title = "إستعراض الكتب لمجموعة " . $_curg ;

$content = '

<div align="center">

<table dir="ltr" cellpadding="0" cellspacing="0" width="100%" style="border-style: solid; border-width: 1pt" bordercolor="#000080">

<tr style="height: 35; font-family: Times New Roman; font-weight: bold; background-color: #CCCCCC">

<td width="40">

<p align="center">قراءة</td>

<td width="40">

<p align="center">تحميل</td>

<td width="109">

<p align="center">التقييم</td>

<td width="50">

<p align="center">مرات التحميل</td>

<td width="194">

<p align="right">  اسم الكتاب</td>

</tr>' ;

$cur_start = ($page * 10);

if ($page==0) $cur_start = ($page*10)+1;

$res = mysql_query("SELECT * FROM tbl_books WHERE fg=$lgroub limit $cur_start,10") ;

$resx = mysql_query("SELECT * FROM tbl_books WHERE fg=$lgroub") ;

$totpages = (mysql_num_rows($resx )/10) - 1 ;

if ($res) {

while($lROW = mysql_fetch_assoc($res)) {

$content .= '

<tr style="height: 30; font-family: Tahoma; font-size: 10pt; color: #000080; border: 1px solid #999999; padding: 1px">

<td width="40">

<p align="center"><a href="upload/' . $lROW["filepath"] . '">قراءة</a></td>

<td width="40">

<p align="center"><a href="download.php?&id=' . $lROW["fid"] . '">تحميل</a></td>

<td width="109">

<p align="center"><span lang="en-us">' . do_stars($lROW["fvote"]) . '</span></td>

<td width="50">

<p align="center"><span lang="en-us">' . $lROW["floadscount"] . '</span></td>

<td width="194">

<p align="right"><span lang="en-us">' . $lROW["fname"] . '</span></td>

</tr>' ;

}

}

$content .= '</table></div>';

// paging -------------------------------------->

$content .= '<table><tr>

<td>' ;

if ($page<$totpages) $content .= '<a href="?action=openg&lgroub=' . $lgroub . '&page=' . ($page+1) . '">التالي</a>' ;

$content .= ' </td>

<td width="100%">

</td>

<td>';

if ($page>0) $content .= '<a href="?action=openg&lgroub=' . $lgroub . '&page=' . ($page-1) . '">السابق</a>' ;

$content .= '</td>

</tr></table>';

// paging -------------------------------------->

$content .= '<br/><a href="?action=openg&add=1&lgroub=' . $lgroub . '">إضافة كتاب</a>';

}

if ($ladd) {

$page_title = "إضافة كتاب جديد" ;

$content = '<form action="?action=openg&form=1&lgroub=' . $lgroub . '" method="post" enctype="multipart/form-data" dir="rtl" style="margin:0">

<table>

<tr><td><label style="width:100">اسم الكتاب<label></td><td><input type="text" name="txtbook" style="width:200"></td></tr>

<tr><td><label style="width:100">الكتاب<label></td><td><input type="file" name="F1" style="width:200"></td></tr>

<tr><td><input type="submit" value="إضافة كتاب"></td></tr>

</table>

</form>' ;

}

if ($lform) {

$page_title = "إضافة كتاب جديد" ;

if ($_POST["txtbook"] && $_FILES["F1"]["name"] ) {

mysql_query("INSERT INTO tbl_books SET fname='" . $_POST["txtbook"] . "' , fg = '$lgroub'") or die(mysql_error()) ;

$_nid = mysql_insert_id() ;

if ($_nid)

{

if ($_FILES['F1']['name'])

{

$nfilename = $_FILES['F1']['name'];

$nfilename = "newbook_$_nid" . substr($nfilename, (strlen($nfilename) - 3) - 1, 4);

$uploadfile = "upload/" . $nfilename;

@move_uploaded_file($_FILES['F1']['tmp_name'], $uploadfile);

//=========

mysql_query("UPDATE tbl_books SET filepath = '$nfilename' WHERE fid = $_nid");

} //@copy

}

$content = '<b><font face="Tahoma" size="2" color="#008000">تم إضافة الكتاب بنجاح</font></b>';

$content .= '<br/><a href="?action=openg&add=1&lgroub=' . $lgroub . '">إضافة كتاب جديد</a>';

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">لايمكن الحفظ بسبب نقص البيانات</font></b>';

$content .= '<br/><a href="?action=openg&lgroub=' . $lgroub . '">العودة</a>';

}

}

//================================================== ===

} else {

$page_title = "رسالة إدارية" ;

$content = '<b><font face="Tahoma" size="2" color="#FF0000">وصول غير مصرح يتوجب عليك التسجيل</font></b>';

}

}

//================================================== ================================

// BROWS books <------------

//================================================== ================================

//================================================== ================================

// BROWS ENGLISH CATG ------------>

//================================================== ================================

if ($action=="gen") {

if ($_SESSION["islogin"]=="yes") {

$ladd = $_GET["add"] ;

$lform = $_GET["form"] ;

if (!$ladd && !$lform) {

$page_title = "Browsing books categories" ;

$content = '<ul>' ;

$res = mysql_query("SELECT * FROM tblgen") ;

if ($res) {

while($lROW = mysql_fetch_assoc($res)) {

$content .= '<li><a href="?action=opengen&lgroub=' . $lROW["fid"] . '">' . $lROW["fname"] . '</a></li>';

}

}

$content .= '</ul>';

$content .= '<br/><a href="?action=gen&add=1">Add category</a>';

}

if ($ladd) {

$page_title = "Add new category" ;

$content = '<form action="?action=gen&form=1" method="post" enctype="application/x-www-form-urlencoded" style="margin:0">

<table>

<tr><td><label style="width:100">Category name<label></td><td><input type="text" name="txtg" style="width:200"></td></tr>

<tr><td><input type="submit" value="Add category"></td></tr>

</table>

</form>' ;

}

if ($lform) {

$page_title = "Add new category" ;

if ($_POST["txtg"]) {

mysql_query("INSERT INTO tblgen (fname) VALUES ('{$_POST["txtg"]}')") ;

$content = '<b><font face="Tahoma" size="2" color="#008000">Category added successfully</font></b>';

$content .= '<br/><a href="?action=gen&add=1">Add new category</a>';

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">Error : data not complete </font></b>';

$content .= '<br/><a href="?action=gen">back</a>';

}

}

//================================================== ===

} else {

$page_title = "Administration massege" ;

$content = '<b><font face="Tahoma" size="2" color="#FF0000">unauthorized access to this page</font></b>';

}

}

//================================================== ================================

// BROWS ENGLISH CATG <------------

//================================================== ================================

//================================================== ================================

// BROWS ENGLISH books ------------>

//================================================== ================================

if ($action=="opengen") {

if ($_SESSION["islogin"]=="yes") {

$ladd = $_GET["add"] ;

$lform = $_GET["form"] ;

$lgroub = $_GET["lgroub"] ;

$page = $_GET["page"];

if (!$page) $page= 0;

// جلب اسم المجموعة

$lxres = mysql_query("SELECT fname FROM tblgen WHERE fid=$lgroub") ;

$lr = mysql_fetch_assoc($lxres) ;

$_curg = $lr["fname"];

//--------------------------

if (!$ladd && !$lform) {

$page_title = "Showing Category books .. " . $_curg ;

$content = '

<div align="center">

<table cellpadding="0" cellspacing="0" width="100%" style="border-style: solid; border-width: 1pt" bordercolor="#000080">

<tr style="height: 35; font-family: Times New Roman; font-weight: bold; background-color: #CCCCCC">

<td width="40">

<p align="center">read</td>

<td width="80">

<p align="center">download</td>

<td width="109">

<p align="center">rate</td>

<td width="40">

<p align="center">No downloads</td>

<td width="194">

<p align="left"> Book name</p></td>

</tr>' ;

$cur_start = ($page * 10);

if ($page==0) $cur_start = ($page*10)+1;

$res = mysql_query("SELECT * FROM tbl_booksen WHERE fg=$lgroub limit $cur_start,10") ;

$resx = mysql_query("SELECT * FROM tbl_booksen WHERE fg=$lgroub") ;

$totpages = (mysql_num_rows($resx )/10)-1;

if ($res) {

while($lROW = mysql_fetch_assoc($res)) {

$content .= '

<tr style="height: 30; font-family: Tahoma; font-size: 10pt; color: #000080; border: 1px solid #999999; padding: 1px">

<td width="40">

<p align="center"><a href="upload/' . $lROW["filepath"] . '">Read</a></td>

<td width="80">

<p align="left"><a href="downloaden.php?&id=' . $lROW["fid"] . '">Download</a></td>

<td width="109">

<p align="center"><span lang="en-us">' . do_stars($lROW["fvote"]) . '</span></td>

<td width="50">

<p align="center"><span lang="en-us">' . $lROW["floadscount"] . '</span></td>

<td width="194">

<p align="left"><span lang="en-us"> ...' . substr($lROW["fname"] , 0 , 20 ) . '</span></p></td>

</tr>' ;

}

}

$content .= '</table></div>';

// paging -------------------------------------->

$content .= '<table><tr>

<td>' ;

if ($page<$totpages) $content .= '<a href="?action=opengen&lgroub=' . $lgroub . '&page=' . ($page+1) . '">next</a>' ;

$content .= ' </td>

<td width="100%">

</td>

<td>';

if ($page>0) $content .= '<a href="?action=opengen&lgroub=' . $lgroub . '&page=' . ($page-1) . '">back</a>' ;

$content .= '</td>

</tr></table>';

// paging -------------------------------------->

$content .= '<br/><a href="?action=opengen&add=1&lgroub=' . $lgroub . '">Add new book</a>';

}

if ($ladd) {

$page_title = "add new book" ;

$content = '<form action="?action=opengen&form=1&lgroub=' . $lgroub . '" method="post" enctype="multipart/form-data" style="margin:0">

<table>

<tr><td><label style="width:100">Book name<label></td><td><input type="text" name="txtbook" style="width:200"></td></tr>

<tr><td><label style="width:100">book file<label></td><td><input type="file" name="F1" style="width:200"></td></tr>

<tr><td><input type="submit" value="add .. "></td></tr>

</table>

</form>' ;

}

if ($lform) {

$page_title = "Add new book" ;

if ($_POST["txtbook"] && $_FILES["F1"]["name"] ) {

mysql_query("INSERT INTO tbl_booksen SET fname='" . $_POST["txtbook"] . "' , fg = '$lgroub'") or die(mysql_error()) ;

$_nid = mysql_insert_id() ;

if ($_nid)

{

if ($_FILES['F1']['name'])

{

$nfilename = $_FILES['F1']['name'];

$nfilename = "newbooken_$_nid" . substr($nfilename, (strlen($nfilename) - 3) - 1, 4);

$uploadfile = "upload/" . $nfilename;

@move_uploaded_file($_FILES['F1']['tmp_name'], $uploadfile);

//=========

mysql_query("UPDATE tbl_booksen SET filepath = '$nfilename' WHERE fid = $_nid");

} //@copy

}

$content = '<b><font face="Tahoma" size="2" color="#008000">Book add successfully</font></b>';

$content .= '<br/><a href="?action=opengen&add=1&lgroub=' . $lgroub . '">Add new book</a>';

} else {

$content = '<b><font face="Tahoma" size="2" color="#FF0000">Error : data not complete</font></b>';

$content .= '<br/><a href="?action=opengen&lgroub=' . $lgroub . '">Back</a>';

}

}

//================================================== ===

} else {

$page_title = "Administration massege" ;

$content = '<b><font face="Tahoma" size="2" color="#FF0000">unauthorized access to this page</font></b>';

}

}

//================================================== ================================

// BROWS ENGLISH books <------------

//================================================== ================================

//================================================== ================================

// SEARCH books ------------>

//================================================== ================================

if ($action=="search") {

if ($_SESSION["islogin"]=="yes") {

$lbookname = $_POST["txtbookname"] ;

$page = $_GET["page"];

if (!$page) $page= 0;

$page_title = "نتائج البحث عن : " . $lbookname ;

$content = '

<div align="center">

<table dir="ltr" cellpadding="0" cellspacing="0" width="100%" style="border-style: solid; border-width: 1pt" bordercolor="#000080">

<tr style="height: 35; font-family: Times New Roman; font-weight: bold; background-color: #CCCCCC">

<td width="40">

<p align="center">قراءة</td>

<td width="40">

<p align="center">تحميل</td>

<td width="109">

<p align="center">التقييم</td>

<td width="50">

<p align="center">مرات التحميل</td>

<td width="194">

<p align="right">  اسم الكتاب</td>

</tr>' ;

$cur_start = ($page * 10);

if ($page==0) $cur_start = 1;

$res = mysql_query("SELECT * FROM tbl_books WHERE fname like '%$lbookname%'") ;

$resx = mysql_query("SELECT * FROM tbl_books WHERE fname like '%$lbookname%'") ;

@$totpages = (mysql_num_rows($resx )/10) - 1 ;

if ($res) {

while($lROW = mysql_fetch_assoc($res)) {

$content .= '

<tr style="height: 30; font-family: Tahoma; font-size: 10pt; color: #000080; border: 1px solid #999999; padding: 1px">

<td width="40">

<p align="center"><a href="upload/' . $lROW["filepath"] . '">قراءة</a></td>

<td width="40">

<p align="center"><a href="download.php?&id=' . $lROW["fid"] . '">تحميل</a></td>

<td width="109">

<p align="center"><span lang="en-us">' . do_stars($lROW["fvote"]) . '</span></td>

<td width="50">

<p align="center"><span lang="en-us">' . $lROW["floadscount"] . '</span></td>

<td width="194">

<p align="right"><span lang="en-us">' . $lROW["fname"] . '</span></td>

</tr>' ;

}

}

$content .= '</table></div>';

// paging -------------------------------------->

} else {

$page_title = "رسالة إدارية" ;

$content = '<b><font face="Tahoma" size="2" color="#FF0000">وصول غير مصرح يتوجب عليك التسجيل</font></b>';

}

}

?>

<html dir="rtl">

<head>

<meta http-equiv="Content-Type" content="text/html; charset=windows-1256">

<meta http-equiv="Content-Language" content="ar-sa">

<title>المكتبة الالكترونية</title>

<script>

function dohelp() {

pop = window.open("help.htm",'helpwindow','width=400,hei ght=600') ;

}

</script>

</head>

<body topmargin="0" leftmargin="0" rightmargin="0" bottommargin="0" marginwidth="0" marginheight="0">

<table border="0" width="100%" cellspacing="0" cellpadding="0" height="100%">

<tr>

<td>

<table border="0" cellpadding="0" width="100%" height="100%" style="border-collapse: collapse">

<tr>

<td>

<img border="0" src="images/styel2_04.jpg" width="482" height="158"></td>

<td>

<table border="0" cellpadding="0" cellspacing="0" width="100%" height="100%">

<tr>

<td>

<img border="0" src="images/styel2_03.jpg" width="90" height="30"></td>

</tr>

<tr>

<td>

<img border="0" src="images/styel2_05.jpg" width="90" height="33" onClick="dohelp();" style="cursortongue.gifointer "></td>

</tr>

<tr>

<td>

<img border="0" src="images/styel2_06.jpg" width="90" height="95"></td>

</tr>

</table>

</td>

<td background="images/styel2_02.jpg" width="100%" valign="top" style="padding:0"> 

</td>

<td>

<img border="0" src="images/styel2_01.jpg" width="168" height="158"></td>

</tr>

</table>

</td>

</tr>

<tr>

<td height="100%">

<table border="0" cellpadding="0" cellspacing="0" width="100%" height="100%">

<tr>

<td background="images/styel2_09.jpg">

<img border="0" src="images/styel2_09.jpg" width="40" height="15"></td>

<td width="100%">

<table border="0" cellpadding="0" width="100%" height="100%" style="border-collapse: collapse">

<tr>

<td valign="top">

<table border="0" cellpadding="0" width="176" height="100" style="border-collapse: collapse">

<tr>

<td background="styel2_13.jpg" height="34" dir="rtl">

<font color="#FFFFFF"><b> القائمة الرئيسية</b></font>

</td>

</tr>

<tr>

<td background="images/styel2_16.jpg" height="100%" valign="top">

<table border="0" cellpadding="0" width="100%" height="100%" style="border-collapse: collapse">

<tr>

<td><a href="?action=newreg">

<img border="0" src="images/styel2_18.jpg" width="176" height="28"></a></td>

</tr>

<tr>

<td><a href="?action=login">

<img border="0" src="images/styel2_19.jpg" width="176" height="28"></a></td>

</tr>

<tr>

<td><a href="?action=g">

<img border="0" src="images/styel2_20.jpg" width="176" height="28"></a></td>

</tr>

<tr>

<td><a href="?action=gen">

<img border="0" src="images/styel2_21.jpg" width="176" height="32"></a></td>

</tr>

</table>

</td>

</tr>

<tr>

<td>

<img border="0" src="images/styel2_23.jpg" width="176" height="10"></td>

</tr>

</table>

<p align="center">

<form action="?action=search" method="post" enctype="application/x-www-form-urlencoded" dir="rtl" style="margin:0">

<table>

<tr><td><label style="width:80">اسم الكتاب :<label></td></tr><tr><td><input type="text" name="txtbookname" style="width:100"><input type="submit" value="البحث"></td></tr>

</table>

</form>

</p>

<p align="center">

<marquee direction="right" >

<img src="images/book2.jpg" width="100" hight = "180">

<img src="images/book3.jpg" width="100" hight = "180">

<img src="images/book5.jpg" width="100" hight = "180">

<img src="images/book6.jpg" width="100" hight = "180">

<img src="images/book8.jpg" width="100" hight = "180">

<img src="images/book9.jpg" width="100" hight = "180">

<img src="images/book10.jpg" width="100" hight = "180">

<img src="images/book11.jpg" width="100" hight = "180">

<img src="images/book12.jpg" width="100" hight = "180">

</marquee></p>

<table border="0" cellpadding="0" width="176" height="100" style="border-collapse: collapse">

<tr>

<td background="styel2_13.jpg" height="34" dir="rtl">

<font color="#FFFFFF"><b>  تسجيل الدخول</b></font></td>

</tr>

<tr>

<td background="images/styel2_16.jpg" height="100%" valign="top" dir="rtl" style="padding: 3px">

<form action="?action=login" method="POST" enctype="application/x-www-form-urlencoded" dir="rtl" style="margin:0">

<input name ="form" type="hidden" value="1">

<table width="100%" height="100%" style="border-collapse: collapse" dir="rtl">

<tr><td>

<label style="width:100; font-weight:700">اسم المستخدم : </label></td></tr>

<tr><td>

<input type="text" name="txtusername" size="20"></td></tr>

<tr><td>

<label style="width:100; font-weight:700">كلمة المرور : </label></td></tr>

<tr><td>

<input type="text" name="txtpassword" size="20"></td></tr>

<tr><td><input type="submit" value="تسجيل الدخول"></td></tr>

</table>

</form>

</td>

</tr>

<tr>

<td>

<img border="0" src="images/styel2_23.jpg" width="176" height="10"></td>

</tr>

</table>

</td>

<td width="100%" valign="top" style="padding: 5px">

<table border="1" cellpadding="0" cellspacing="0" width="100%" height="100%" bordercolor="#495674">

<tr>

<td height="30" bgcolor="#9696C1" dir="rtl" style="font-family: Times New Roman; font-size: 12pt; font-weight: bold"><span lang="en-us"><?php echo $page_title ; ?></span></td>

</tr>

<tr>

<td height="100%" bgcolor="#D1D1D1" dir="rtl" valign="top" style="font-family: Times New Roman; font-size: 12pt; font-weight: bold; padding: 10px"><span lang="en-us"><?php echo $content ; ?></span></td>

</tr>

</table>

</td>

</tr>

</table>

</td>

<td background="images/styel2_07.jpg">

<img border="0" src="images/styel2_07.jpg" width="38" height="15"></td>

</tr>

</table>

</td>

</tr>

<tr>

<td>

<table border="0" cellpadding="0" cellspacing="0" width="100%" height="100%">

<tr>

<td>

<img border="0" src="images/styel2_29.jpg" width="53" height="39"></td>

<td background="images/styel2_26.jpg" width="100%"> </td>

<td>

<img border="0" src="images/styel2_25.jpg" width="54" height="39"></td>

</tr>

</table>

</td>

</tr>

</table>

</body>

</html>

ولكم جزيل الشكر

مواضيع مشابهة