if($_POST['task'] == "insert") { mysql_query("INSERT INTO `users` ( `id` , `firstname` , `lastname` , `email` , `password` , `role` , `rights` , `comment` ) VALUES ( NULL , '".$_POST['firstname']."', '".$_POST['lastname']."', '".$_POST['email']."', '".$_POST['password']."', '', '".$_POST['rights']."', '".$_POST['comment']."' )"); log_action($_SESSION['user_email'],"Created User: ".$_POST['email']); } elseif($_POST['task'] == "editit") { mysql_query("update users set firstname = '".$_POST['firstname']."',lastname = '".$_POST['lastname']."',email = '".$_POST['email']."',password = '".$_POST['password']."',rights = '".$_POST['rights']."',comment = '".$_POST['comment']."' where id = '".$_POST['id']."'"); log_action($_SESSION['user_email'],"Edited User: ".$_POST['email']); } elseif($_GET['task'] == "delete") { $result = mysql_query("select email from users where id = '".$_GET['id']."'"); $row = mysql_fetch_object($result); mysql_query("delete from users where id = '".$_GET['id']."'"); log_action($_SESSION['user_email'],"Deleted User: ".$row->email); } ?>