View file wapirate/wml/modxcp.php

File size: 9.54Kb
<?php

include("head.php");

$sta = getstatusname($uid);

if(!isstatus7(getuid_sid($sid)))

  {

    echo "<card id=\"main\" title=\"wapirate\">";

      echo "<p align=\"center\">";

      echo "You are not a mod<br/>";

      echo "<br/>";

      echo "<a href=\"index.php\">Home</a>";

      echo "</p>";

      echo "</card>";

      echo "</wml>";

      exit();

 }



    addonline(getuid_sid($sid),"Main Page","");



/////////////////////////////////MOD X CP

if($action=="modxcp")

{

  addonline(getuid_sid($sid),"Main Page","");

    echo "<card id=\"main\" title=\"$sitename\">";

  echo "<p align=\"center\">";

  echo "<b>$sta CP</b>";

  echo "</p>";

  echo "<p>";

  if(isstatus7(getuid_sid($sid)))

  {

    $nrpm = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_private WHERE reported='1'"));

	echo "<a href=\"modcp.php?action=rpm\">&#187;Pr. Messages [$nrpm[0]]</a><br/>";

	$nrps = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_posts WHERE reported='1'"));

    echo "<a href=\"modcp.php?action=rps\">&#187;Posts [$nrps[0]]</a><br/>";

    $nrtp = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_topics WHERE reported='1'"));

    echo "<a href=\"modcp.php?action=rtp\">&#187;Topics [$nrtp[0]]</a><br/>";

	$noi = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_vault"));

    echo "<a href=\"lists.php?action=vault\">&#187;Users Vaults [$noi[0]]</a><hr/>";

   echo "<a href=\"modxcp.php?action=chuinfo\">&#187;Change User Info</a><br/>";

 	echo "<a href=\"modxcp.php?action=addspam\">&#187;Add Spam Block</a><br/>";

    echo "<a href=\"lists.php?action=spam\">&#187;Edit Spam Block</a><br/>";

 echo "(more options on xhtml)<br/>";

  }else{

    echo "You are not a Mod";

mysql_query("INSERT INTO ibwf_mlog SET action='hacks', details='<b>".getnick_uid(getuid_sid($sid))."</b> Attempted To Hack Mod X (index)', actdt='".time()."'");

  }

  echo "</p>";

  echo "<p align=\"center\">";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

  echo "</p>";

  echo "</card>";

}

/////////////////////////////////////spam

else if($action=="addspam")

{

    echo "<card id=\"main\" title=\"$sta CP\">";

    echo "<p align=\"center\">";

    echo "<b>Add Spam Block</b><br/><br/>";

    echo "Site:<input name=\"smlcde\" maxlength=\"30\"/><br/>";

    echo "Change To:<input name=\"smlsrc\" maxlength=\"200\"/><br/>";

    echo "<anchor>Add";

    echo "<go href=\"modxproc.php?action=addspam\" method=\"post\">";

    echo "<postfield name=\"smlcde\" value=\"$(smlcde)\"/>";

    echo "<postfield name=\"smlsrc\" value=\"$(smlsrc)\"/>";

    echo "</go></anchor>";

    echo "<br/><br/><a href=\"modxcp.php?action=modxcp\"><img src=\"images/admn.gif\" alt=\"*\"/>";

  echo "$sta CP</a><br/>";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

  echo "Home</a>";

  echo "</p>";

    echo "</card>";

}



/////////////////////////////////user info



else if($action=="chuinfo")

{

    echo "<card id=\"main\" title=\"$sta CP\">";

    echo "<p align=\"center\">";

    echo "Type user nickname<br/><br/>";

    echo "User: <input name=\"unick\" format=\"*x\" maxlength=\"15\"/><br/>";

    echo "<anchor>[FIND]";

    echo "<go href=\"modxcp.php?action=acui\" method=\"post\">";

    echo "<postfield name=\"unick\" value=\"$(unick)\"/>";

    echo "</go></anchor>";

    echo "<br/><br/><a href=\"modxcp.php?action=modxcp\"><img src=\"images/admn.gif\" alt=\"*\"/>";

  echo "$sta CP</a><br/>";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

  echo "Home</a>";

  echo "</p>";

    echo "</card>";

}



//////////////////////////////////////Change User info



else if($action=="acui")

{

   echo "<card id=\"main\" title=\"$sta CP\">";

    echo "<p align=\"center\">";

    $unick = $_POST["unick"];

    $tid = getuid_nick($unick);

    if($tid==0)

    {

      echo "<img src=\"images/notok.gif\" alt=\"x\"/>User Does Not exist<br/>";

    }else{

      echo "</p>";

      echo "<p>";

      echo "<a href=\"modxcp.php?action=chubi&amp;who=$tid\">&#187;$unick's Profile</a><br/>";

      /*$judg = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_judges WHERE uid='".$tid."'"));

      if($judg[0]>0)

      {

      echo "<a href=\"admproc.php?action=deljdg&amp;who=$tid\">&#187;Remove $unick From Judges List</a><br/>";

      }else{

        echo "<a href=\"admproc.php?action=addjdg&amp;who=$tid\">&#187;Make $unick judge</a><br/>";

      }*/

      //echo "<a href=\"admincp.php?action=addtog&amp;who=$tid\">&#187;Add  $unick to a group</a><br/>";

      //echo "<a href=\"admincp.php?action=umset&amp;who=$tid\">&#187;$unick's Mod. Settings</a><br/>";

	  /*echo "<a href=\"admproc.php?action=delxp&amp;who=$tid\">&#187;Delete $unick's posts</a><br/>";

      echo "<a href=\"admproc.php?action=delu&amp;who=$tid\">&#187;Delete $unick</a><br/>";*/

      echo "</p>";

      echo "<p align=\"center\">";

    }

    echo "<a href=\"modxcp.php?action=chuinfo\">";

  echo "Users Info</a><br/>";

    echo "<a href=\"modxcp.php?action=modxcp\"><img src=\"images/admn.gif\" alt=\"*\"/>";

  echo "$sta CP</a><br/>";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

  echo "Home</a>";

  echo "</p>";

    echo "</card>";

}



////////////////////////////////////////////



else if($action=="chubi")

{

    echo "<card id=\"main\" title=\"$sta CP\">";

    $who = $_GET["who"];

    $unick = getnick_uid($who);

    echo "<onevent type=\"onenterforward\">";

    $avat = getavatar($who);

    $email = mysql_fetch_array(mysql_query("SELECT email FROM ibwf_users WHERE id='".$who."'"));

    $site = mysql_fetch_array(mysql_query("SELECT site FROM ibwf_users WHERE id='".$who."'"));

    $bdy = mysql_fetch_array(mysql_query("SELECT birthday FROM ibwf_users WHERE id='".$who."'"));

    $uloc = mysql_fetch_array(mysql_query("SELECT location FROM ibwf_users WHERE id='".$who."'"));

    $usig = mysql_fetch_array(mysql_query("SELECT signature FROM ibwf_users WHERE id='".$who."'"));

    $sx = mysql_fetch_array(mysql_query("SELECT sex FROM ibwf_users WHERE id='".$who."'"));

    $perm = mysql_fetch_array(mysql_query("SELECT hidemyperm FROM ibwf_users WHERE id='".$who."'"));

  echo "<refresh>

        <setvar name=\"unick\" value=\"$unick\"/>

        <setvar name=\"savat\" value=\"$avat\"/>

        <setvar name=\"semail\" value=\"$email[0]\"/>

        <setvar name=\"usite\" value=\"$site[0]\"/>

        <setvar name=\"ubday\" value=\"$bdy[0]\"/>

        <setvar name=\"uloc\" value=\"$uloc[0]\"/>

        <setvar name=\"usig\" value=\"$usig[0]\"/>

        <setvar name=\"perm\" value=\"$perm[0]\"/>

        <setvar name=\"sx\" value=\"$sx[0]\"/>

         <setvar name=\"npwd\" value=\"\"/>

   ";

  echo "</refresh></onevent>";

    echo "<p>";

    echo "Nickname: $unick<br/>";

    echo "Avatar: <input name=\"savat\" maxlength=\"1000\"/><br/>";

    echo "E-Mail: <input name=\"semail\" maxlength=\"1000\"/><br/>";

   //echo "Downloads Rep: <input name=\"usite\" maxlength=\"1000\"/><br/>";

    echo "Birthday<small>(YYYY-MM-DD)</small>: <input name=\"ubday\" maxlength=\"50\"/><br/>";

    echo "Location: <input name=\"uloc\" maxlength=\"1000\"/><br/>";

    echo "Signature: <input name=\"usig\" maxlength=\"1000\"/><br/>";

    echo "Sex: <select name=\"usex\" value=\"$sx[0]\">";

    echo "<option value=\"M\">Male</option>";

    echo "<option value=\"F\">Female</option>";

    echo "</select><br/>";

if(isstatus9(getuid_sid($sid))){

    echo "Privileges: <select name=\"perm\" value=\"$perm[0]\">";

    echo "<option value=\"0\">User</option>";

    echo "<option value=\"1\">$status1</option>";

    echo "<option value=\"2\">$status2</option>";

    echo "<option value=\"3\">$status3</option>";

    echo "<option value=\"4\">$status4</option>";

    echo "</select><br/>";

}

    echo "<anchor>Update";

    echo "<go href=\"modxproc.php?action=uprof&amp;who=$who\" method=\"post\">";

    echo "<postfield name=\"unick\" value=\"$unick\"/>";

    echo "<postfield name=\"savat\" value=\"$(savat)\"/>";

    echo "<postfield name=\"semail\" value=\"$(semail)\"/>";

    echo "<postfield name=\"usite\" value=\"$(usite)\"/>";

    echo "<postfield name=\"ubday\" value=\"$(ubday)\"/>";

    echo "<postfield name=\"uloc\" value=\"$(uloc)\"/>";

    echo "<postfield name=\"usig\" value=\"$(usig)\"/>";

    echo "<postfield name=\"usex\" value=\"$(usex)\"/>";

    echo "<postfield name=\"perm\" value=\"$(perm)\"/>";

    echo "</go></anchor>";

    echo "<br/><br/>";

    echo "</p>";

    echo "<p align=\"center\">";

    echo "<a href=\"modxcp.php?action=chuinfo\">";

  echo "Users Info</a><br/>";

    echo "<a href=\"modxcp.php?action=modxcp\"><img src=\"images/admn.gif\" alt=\"*\"/>";

  echo "$sta CP</a><br/>";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

  echo "Home</a>";

  echo "</p>";

    echo "</card>";

    

}

else{

   echo "<card id=\"main\" title=\"Wapirate\">";

  echo "<p align=\"center\">";

  echo "I don't know how did you get into here, but there's nothing to show<br/><br/>";

  echo "<a href=\"index.php?action=main\"><img src=\"images/home.gif\" alt=\"*\"/>";

echo "Home</a>";

mysql_query("INSERT INTO ibwf_mlog SET action='hacks', details='<b>".getnick_uid(getuid_sid($sid))."</b> Attempted To Hack modXcp', actdt='".time()."'");

  echo "</p></card>";

}



?>

</wml>