FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
HackMe-SQL-Injection-Challenges/imadd.php at master · breakthenet/HackMe-SQL-Injection-Challenges · GitHub
Uh oh!
There was an error while loading.
Please reload this page
.
breakthenet
/
HackMe-SQL-Injection-Challenges
Public
Notifications
You must be signed in to change notification settings
Fork
46
Star
414
Code
Issues
0
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
HackMe-SQL-Injection-Challenges
/
imadd.php
Copy path
More file actions
More file actions
Latest commit
History
History
History
executable file
·
78 lines (77 loc) · 2.33 KB
Breadcrumbs
HackMe-SQL-Injection-Challenges
/
imadd.php
Copy path
File metadata and controls
executable file
·
78 lines (77 loc) · 2.33 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
<?php
session_start
();
require
"
global_func.php
"
;
if
(
$
_SESSION
[
'
loggedin
'
] ==
0
)
{
header
(
"
Location: login.php
"
);
exit
;
}
$
userid
=
$
_SESSION
[
'
userid
'
];
require
"
header.php
"
;
$
h
=
new
headers
;
$
h
->
startheaders
();
include
"
mysql.php
"
;
global
$
c
;
$
is
=
mysql_query
(
"
SELECT u.*,us.* FROM users u LEFT JOIN userstats us ON u.userid=us.userid WHERE u.userid=
$
userid
"
,
$
c
)
or
die
(
mysql_error
());
$
ir
=
mysql_fetch_array
(
$
is
);
check_level
();
$
fm
=
money_formatter
(
$
ir
[
'
money
'
]);
$
cm
=
money_formatter
(
$
ir
[
'
crystals
'
],
''
);
$
lv
=
date
(
'
F j, Y, g:i a
'
,
$
ir
[
'
laston
'
]);
$
h
->
userdata
(
$
ir
,
$
lv
,
$
fm
,
$
cm
);
$
h
->
menuarea
();
$
_GET
[
'
ID
'
] =
abs
((
int
)
$
_GET
[
'
ID
'
]);
$
_GET
[
'
price
'
] =
abs
((
int
)
$
_GET
[
'
price
'
]);
if
(
$
_GET
[
'
price
'
])
{
$
q
=
mysql_query
(
"
SELECT iv.*,i.* FROM inventory iv LEFT JOIN items i ON iv.inv_itemid=i.itmid WHERE inv_id=
{
$
_GET
[
'
ID
'
]}
and inv_userid=
$
userid
"
,
$
c
);
if
(
mysql_num_rows
(
$
q
) ==
0
)
{
print
"
Invalid Item ID
"
;
}
else
{
$
r
=
mysql_fetch_array
(
$
q
);
mysql_query
(
"
INSERT INTO itemmarket VALUES(NULL,'
{
$
r
[
'
inv_itemid
'
]}
',
$
userid
,
{
$
_GET
[
'
price
'
]}
)
"
,
$
c
);
mysql_query
(
"
UPDATE inventory SET inv_qty=inv_qty-1 WHERE inv_id=
{
$
_GET
[
'
ID
'
]}"
,
$
c
);
mysql_query
(
"
DELETE FROM inventory WHERE inv_qty=0
"
,
$
c
);
mysql_query
(
"
INSERT INTO imarketaddlogs VALUES ( '',
{
$
r
[
'
inv_itemid
'
]}
,
{
$
_GET
[
'
price
'
]}
,
{
$
r
[
'
inv_id
'
]}
,
$
userid
,
"
.
time
()
.
"
, '
{
$
ir
[
'
username
'
]}
added a
{
$
r
[
'
itmname
'
]}
to the itemmarket for
\${
$
_GET
[
'
price
'
]}
')
"
,
$
c
);
print
"
Item added to market.
"
;
}
}
else
{
$
q
=
mysql_query
(
"
SELECT * FROM inventory WHERE inv_id=
{
$
_GET
[
'
ID
'
]}
and inv_userid=
$
userid
"
,
$
c
);
if
(
mysql_num_rows
(
$
q
) ==
0
)
{
print
"
Invalid Item ID
"
;
}
else
{
$
r
=
mysql_fetch_array
(
$
q
);
print
"
Adding an item to the item market...
<form action='imadd.php' method='get'>
<input type='hidden' name='ID' value='
{
$
_GET
[
'
ID
'
]}
' />
Price:
\$
<input type='text' name='price' value='0' /><br />
<input type='submit' value='Add' /></form>
"
;
}
}
$
h
->
endpage
();
Back
|
FazBrowse Home
|
New Git URL