Advertisement
Guest User

asd

a guest
May 15th, 2017
102
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.99 KB | None | 0 0
  1.  
  2. <?php
  3. include 'csrf.class.php';
  4.  
  5. if (isset($_GET['Change'])) {
  6.  
  7. $token_id = $csrf->get_token_id();
  8. $token_value = $csrf->get_token($token_id);
  9.  
  10. // Turn requests into variables
  11. $pass_new = $_GET['password_new'];
  12. $pass_conf = $_GET['password_conf'];
  13.  
  14.  
  15. if (($pass_new == $pass_conf)){
  16. if($csrf->check_valid('get')){
  17.  
  18.  
  19. $pass_new = mysql_real_escape_string($pass_new);
  20. $pass_new = md5($pass_new);
  21.  
  22. $insert="UPDATE `users` SET password = '$pass_new' WHERE user = 'admin';";
  23. $result=mysql_query($insert) or die('<pre>' . mysql_error() . '</pre>' );
  24.  
  25. echo "<pre> Password Changed </pre>";
  26. mysql_close();
  27. }
  28. else{
  29. echo "<pre> Zły token CSRF </pre>";
  30. }
  31. }
  32.  
  33. else{
  34. echo "<pre> Passwords did not match. </pre>";
  35. }
  36.  
  37. }
  38. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement