Guest User

Untitled

a guest
Jan 21st, 2018
73
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.62 KB | None | 0 0
  1. <?php
  2. require_once 'sqllogin.php';
  3. require_once 'passhash.php';
  4. echo <<< _END
  5. <html>
  6. <head>
  7. <title>Index</title>
  8. </head>
  9. <body>
  10. <form method='post' action='index.php'>
  11. Name: <input type='text' name='name' size='10' maxlength='64' /> <br />
  12. Email address: <input type='text' name='email' size='10' maxlength='254' /> <br />
  13. Password: <input type='password' name='password' / size='10'> <br />
  14. Friend code: <input type='text' name='friend1' size='4' maxlength='4' />-<input type='text' name='friend2' size='4' maxlength='4' /><input type='text' name='friend3' size='4' maxlength='4' /><br />
  15. <input type="submit" value="Submit" />
  16. </form>
  17. _END;
  18.  
  19. $db_server = connect();
  20. mysql_select_db($db_database) or die("Unable to select db: " . mysql_error());
  21.  
  22. if (isset($_GET['deleteid'])) {
  23. $delete = $_GET['deleteid'];
  24. $delete = mysql_escape_string($delete);
  25. $deletesql = "DELETE FROM users WHERE uid=" . $delete;
  26. $deleted = mysql_query($deletesql);
  27. if (!$deleted) die ("Database error: " . mysql_error());
  28. }
  29.  
  30. if(isset($_POST['name']) &&
  31. isset($_POST['email']) &&
  32. isset($_POST['password']) &&
  33. isset($_POST['friend1']) &&
  34. isset($_POST['friend2']) &&
  35. isset($_POST['friend3']))
  36. {
  37. $name = $_POST['name'];
  38. $email = $_POST['email'];
  39. $password = $_POST['password'];
  40. $friendcode = $_POST['friend1'] . "-" . $_POST['friend2'] . "-" . $_POST['friend3'];
  41. if (!(strlen($friendcode == 15))) {
  42. $friendcode = "0000-0000-0000";
  43. }
  44. $friendcode = mysql_escape_string($friendcode);
  45. $password = mysql_escape_string($password);
  46. $email = mysql_escape_string($email);
  47. $name = mysql_escape_string($name);
  48. $insert = "INSERT INTO users (friendcode, emailaddress, name) VALUES ('" . $friendcode . "', '" . $email . "', '" . $name . "')";
  49. $inserted = mysql_query($insert);
  50. if (!$inserted) die ("Database error:" . mysql_error());
  51. $id = mysql_insert_id();
  52. $password = passhash($password, $id);
  53. $insert = "UPDATE users SET pass='" . $password . "' WHERE uid='" + $id . "'";
  54. $inserted = mysql_query($insert);
  55. if (!$inserted) die ("Database error:" . mysql_error());
  56. }
  57.  
  58. $returned = mysql_query("SELECT uid,friendcode,emailaddress,name,pass FROM users;");
  59. if (!$returned) die ("Database error:" . mysql_error());
  60. $rows = mysql_num_rows($returned);
  61. for ($j = 0; $j < $rows; ++$j) {
  62. $row = mysql_fetch_row($returned);
  63. echo "Name: " . $row[3] . "<br />";
  64. echo "Email Address: " . $row[2] . "<br />";
  65. echo "UserID: " . $row[0] . "<br />";
  66. echo "Friend Code: " . $row[1] . "<br />";
  67. $link = "<a href='index.php?deleteid=" . $row[0] . "'>Delete</a> <br /><br />";
  68. echo $link;
  69. }
  70. mysql_close($db_server);
  71. echo "</body></html>";
  72.  
  73. ?>
Add Comment
Please, Sign In to add comment