FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
HackMe-SQL-Injection-Challenges/willpdone.php at master · breakthenet/HackMe-SQL-Injection-Challenges · GitHub
Uh oh!
There was an error while loading.
Please reload this page
.
breakthenet
/
HackMe-SQL-Injection-Challenges
Public
Notifications
You must be signed in to change notification settings
Fork
46
Star
414
Code
Issues
0
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
HackMe-SQL-Injection-Challenges
/
willpdone.php
Copy path
More file actions
More file actions
Latest commit
History
History
History
executable file
·
60 lines (59 loc) · 1.47 KB
Breadcrumbs
HackMe-SQL-Injection-Challenges
/
willpdone.php
Copy path
File metadata and controls
executable file
·
60 lines (59 loc) · 1.47 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
<?php
session_start
();
require
"
global_func.php
"
;
if
(
$
_SESSION
[
'
loggedin
'
] ==
0
)
{
header
(
"
Location: login.php
"
);
exit
;
}
$
userid
=
$
_SESSION
[
'
userid
'
];
require
"
header.php
"
;
$
h
=
new
headers
;
$
h
->
startheaders
();
include
"
mysql.php
"
;
global
$
c
;
$
is
=
mysql_query
(
"
SELECT u.*,us.* FROM users u LEFT JOIN userstats us ON u.userid=us.userid WHERE u.userid=
$
userid
"
,
$
c
)
or
die
(
mysql_error
());
$
ir
=
mysql_fetch_array
(
$
is
);
check_level
();
$
fm
=
money_formatter
(
$
ir
[
'
money
'
]);
$
cm
=
money_formatter
(
$
ir
[
'
crystals
'
],
''
);
$
lv
=
date
(
'
F j, Y, g:i a
'
,
$
ir
[
'
laston
'
]);
$
h
->
userdata
(
$
ir
,
$
lv
,
$
fm
,
$
cm
);
$
h
->
menuarea
();
if
(
$
_GET
[
'
action
'
] ==
"
cancel
"
)
{
print
"
You have cancelled your donation. Please donate later...
"
;
}
else
if
(
$
_GET
[
'
action
'
] ==
"
done
"
)
{
if
(!
$
_GET
[
'
tx
'
])
{
die
(
"
Get a life.
"
);
}
$
quantity
=
mysql_real_escape_string
(
stripslashes
(
$
_GET
[
'
quantity
'
]),
$
c
);
mysql_query
(
"
INSERT INTO willplogs VALUES(NULL,
$
userid
,
"
.
time
()
.
"
,'
{
$
quantity
}
');
"
,
$
c
);
if
(
$
_GET
[
'
quantity
'
] ==
'
one
'
)
{
$
q
=
1
;
}
else
if
(
$
_GET
[
'
quantity
'
] ==
'
five
'
)
{
$
q
=
5
;
}
else
{
echo
'
Stop cheating!
'
;
$
h
->
endpage
();
exit
;
}
mysql_query
(
"
INSERT INTO inventory VALUES(NULL,34,
$
userid
,
$
q
)
"
,
$
c
);
print
"
Your will potions have been credited, if you are cheating, we will jail you.
"
;
}
$
h
->
endpage
();
Back
|
FazBrowse Home
|
New Git URL