Advertisement
Guest User

Untitled

a guest
Jul 10th, 2017
77
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.53 KB | None | 0 0
  1. <?php
  2.  
  3. //$username = $_GET['username'];
  4. //$password = $_GET['password'];
  5. //$server = $_GET['server'];
  6.  
  7. /*if(!isset($username, $password, $server))
  8. {
  9. echo("form_incomplete");
  10. die;
  11. }*/
  12.  
  13. $con = mysql_connect("mysql4.000webhost.com", "a7212342_gm", "password1234");
  14.  
  15. if(!$con)
  16. {
  17. echo("Server Connection Failure!");
  18. die;
  19. }
  20. else
  21. {
  22. $querystring = $_GET['input'];
  23. $tableinput = $_GET['table'];
  24. $var1 = $_GET['var1'];
  25. $var2 = $_GET['var2'];
  26.  
  27. mysql_real_escape_string($var1);
  28. mysql_real_escape_string($tableinput);
  29. mysql_real_escape_string($var2);
  30.  
  31. if(!isset($querystring))
  32. {
  33. echo("form_incomplete");
  34. die;
  35. }
  36. else
  37. {
  38. mysql_select_db(a7212342_gm);
  39.  
  40. $words = explode(" ", $querystring);
  41. $words2 = explode(" ", $var2);
  42. if(in_array("SELECT", $words) || in_array("select", $words))
  43. {
  44. // Command is SELECT
  45. $query = "SELECT " . $var1 . " FROM " . $tableinput . " WHERE " . stripslashes($var2);
  46. $result = mysql_query($query) or die(mysql_error());
  47. $i = 0;
  48. $row = mysql_fetch_row($result);
  49. while ($i < mysql_num_fields($result)) {
  50. echo $row[$i] . "|";
  51. $i++;
  52. }
  53. mysql_free_result($result);
  54. }
  55. elseif(in_array("SELECT", $words) || in_array("select", $words) && !in_array("WHERE", $words2))
  56. {
  57. // Command is SELECT
  58. $result = mysql_query("SELECT " . $var1 . " FROM " . $tableinput) or die(mysql_error());
  59. $i = 0;
  60. $row = mysql_fetch_row($result);
  61. while ($i < mysql_num_fields($result)) {
  62. echo $row[$i] . "|";
  63. $i++;
  64. }
  65. mysql_free_result($result);
  66.  
  67. }
  68. elseif(in_array("UPDATE", $words))
  69. {
  70. $command = "UPDATE " . $tableinput . " SET " . $var1 . " WHERE " . $var2;
  71. mysql_query(stripslashes($command)) or die(mysql_error());
  72. }
  73. elseif(in_array("INSERT", $words))
  74. {
  75. $var3 = $_GET['var3'];
  76. $var4 = $_GET['var4'];
  77. $var5 = $_GET['var5'];
  78. $var6 = $_GET['var6'];
  79. $var7 = $_GET['var7'];
  80. $var8 = $_GET['var8'];
  81. $var9 = $_GET['var9'];
  82. $var10 = $_GET['var10'];
  83.  
  84. mysql_real_escape_string($var3);
  85. mysql_real_escape_string($var4);
  86. mysql_real_escape_string($var5);
  87. mysql_real_escape_string($var6);
  88. mysql_real_escape_string($var7);
  89. mysql_real_escape_string($var8);
  90. mysql_real_escape_string($var9);
  91. mysql_real_escape_string($var10);
  92.  
  93. $command = "INSERT INTO " . $tableinput . " ( " . $var1 . ", " . $var2 . ", " . $var3 . ", " . $var4 . ", " . $var5 . " ) VALUES ( '" . $var6 . "', '" . $var7 . "', " . $var8 . ", " . $var9 . ", '" . $var10 . "' )";
  94. mysql_query($command) or die(mysql_error());
  95. }
  96. else
  97. {
  98. echo "Fail!";
  99. }
  100. die;
  101. }
  102. }
  103. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement