View file wapirate/A1/modxproc.php

File size: 6.05Kb
<?php





include("core.php");

include("config.php");





header("Content-type: text/html; charset=ISO-8859-1");

echo "<?xml version=\"1.0\" encoding=\"ISO-8859-1\" ?>";

echo "<!DOCTYPE html PUBLIC \"-//WAPFORUM//DTD XHTML Mobile 1.0//EN\"\"http://www.wapforum.org/DTD/xhtml-mobile10.dtd\">";

echo "<html xmlns=\"http://www.w3.org/1999/xhtml\">";



$addy = "wapirate.net";

connectdb();

$action = $_GET["action"];

$sid = $_GET["sid"];

$uid = getuid_sid($sid);

$theme = mysql_fetch_array(mysql_query("SELECT theme FROM ibwf_users WHERE id='".$uid."'"));

if(!ismodx(getuid_sid($sid)))

  {

     echo "<head>";

    echo "<title>Error!!!</title>";

    echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/red_medium.css\">";

    echo "</head>";

    echo "<body>";

     echo "<div><br/>Doh!<br/></div>";  

      echo "<p align=\"center\">";

      echo "You are not an admin<br/>";

      echo "<br/>";

      echo "<a href=\"index.php\">Home</a>";

      echo "</p>";

    echo "<div>$addy</div>";

    echo "</body>";

    echo "</html>";

      exit();

    }

if(islogged($sid)==false)

    {

     echo "<head>";

    echo "<title>Error!!!</title>";

    echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/red_medium.css\">";

    echo "</head>";

    echo "<body>"; 

      echo "<div><br/>Doh!<br/></div>";    

      echo "<p align=\"center\">";

      echo "You are not logged in<br/>";

      echo "Or Your session has been expired<br/><br/>";

      echo "<a href=\"index.php\">Login</a>";

      echo "</p>";

    echo "<div>$addy</div>";

    echo "</body>";

    echo "</html>";

      exit();

    }

    addonline(getuid_sid($sid),"Main Page","");





///////////////////////////////////spam block

if($action=="addspam"){

$smlcde = $_POST["smlcde"];

$smlsrc = $_POST["smlsrc"];

  echo "<head>";

  echo "<title>wapirate</title>";

  echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/$theme[0]\">";

  echo "</head>";

  echo "<body>";

   echo "<div><br/>Add Spam Block<br/></div>";

echo "<p align=\"center\">";

echo "<br/>";

$res = mysql_query("INSERT INTO ibwf_spam SET scode='".$smlcde."', imgsrc='".$smlsrc."', hidden='0'");

if($res){

echo "<img src=\"images/ok.gif\" alt=\"O\"/>Spam Block added successfully";

}else{

echo "<img src=\"images/notok.gif\" alt=\"X\"/>Error adding Spam Block ";

}

echo "<br/><br/><a href=\"admincp.php?action=addspam&amp;sid=$sid\">";

echo "Add Another Spam Block</a><br/>";

echo "<a href=\"lists.php?action=spam&amp;sid=$sid\">Spam Block List</a><br/>";

echo "<a href=\"index.php?action=modxcp&amp;sid=$sid\"><img src=\"images/admn.gif\" alt=\"*\"/>";

echo "Mod X CP</a><br/>";

echo "<a href=\"index.php?action=main&amp;sid=$sid\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

echo "</p>";

    echo "<div>$addy</div>";

   echo "</body>";

     exit();

}



//////////////////////////////////////delete spam block

else if($action=="delspam"){

$smid = $_GET["smid"];

  echo "<head>";

  echo "<title>wapirate</title>";

  echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/$theme[0]\">";

  echo "</head>";

  echo "<body>"; 

  echo "<div><br/>Delete Spam Block<br/></div>";

echo "<p align=\"center\">";

echo "<br/>";

$res = mysql_query("DELETE FROM ibwf_spam WHERE id='".$smid."'");

if($res){

echo "<img src=\"images/ok.gif\" alt=\"O\"/>Spam Block deleted successfully";

}else{

echo "<img src=\"images/notok.gif\" alt=\"X\"/>Error deleting Spam Block ";

}

echo "<br/><a href=\"lists.php?action=spam&amp;sid=$sid\">Spam Block List</a><br/>";

echo "<br/><br/><a href=\"index.php?action=modxcp&amp;sid=$sid\"><img src=\"images/admn.gif\" alt=\"*\"/>";

echo "Mod X CP</a><br/>";

echo "<a href=\"index.php?action=main&amp;sid=$sid\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

echo "</p>";

    echo "<div>$addy</div>";

   echo "</body>";

     exit();

}

//////////////////////////////////////////Update profile



else if($action=="uprof"){

$who = $_GET["who"];

$unick = $_POST["unick"];

$savat = $_POST["savat"];

$semail = $_POST["semail"];

$ubday = $_POST["ubday"];

$uloc = $_POST["uloc"];

$usig = $_POST["usig"];

$usex = $_POST["usex"];

  echo "<head>";

  echo "<title>wapirate</title>";

  echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/$theme[0]\">";

  echo "</head>";

  echo "<body>"; 

    echo "<div><br/>$unick's Profile<br/></div>";

echo "<p align=\"center\">";



$res = mysql_query("UPDATE ibwf_users SET avatar='".$savat."', email='".$semail."', birthday='".$ubday."', location='".$uloc."', signature='".$usig."', sex='".$usex."' WHERE id='".$who."'");

if($res){

echo "<img src=\"images/ok.gif\" alt=\"o\"/>$unick's profile was updated successfully<br/>";

}else{

echo "<img src=\"images/notok.gif\" alt=\"x\"/>Error updating $unick's profile<br/>";

}

echo "<br/><a href=\"modxcp.php?action=chuinfo&amp;sid=$sid\">";

echo "Users Info</a><br/>";

echo "<a href=\"index.php?action=modxcp&amp;sid=$sid\"><img src=\"images/admn.gif\" alt=\"*\"/>";

echo "Mod X CP</a><br/>";

echo "<a href=\"index.php?action=main&amp;sid=$sid\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

echo "</p>";

    echo "<div>$addy</div>";

   echo "</body>";

     exit();

}



else{

  echo "<head>";

  echo "<title>wapirate</title>";

  echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../themes/$theme[0]\">";

  echo "</head>";

  echo "<body>"; 

    echo "<div><br/>Doh!<br/></div>";

echo "<p align=\"center\">";

echo "I don't know how you got in here, but there's nothing to show<br/><br/>";

echo "<a href=\"index.php?action=main&amp;sid=$sid\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

mysql_query("INSERT INTO ibwf_mlog SET action='hacks', details='<b>".getnick_uid(getuid_sid($sid))."</b> Attempted To Hack modXproc', actdt='".time()."'");

echo "</p>";

    echo "<div>$addy</div>";

   echo "</body>";

     exit();

}

  echo "</html>";



?>