Skip to content

Commit e6504fa

Browse files
committed
Simplify database query from admin panel.
1 parent 8576cc1 commit e6504fa

3 files changed

Lines changed: 25 additions & 13 deletions

File tree

admin/acc.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -368,13 +368,13 @@
368368
$search = clean_var(stripslashes($_POST['search_account']));
369369

370370
$queryBuildWhere = !empty($_POST['search_type'])
371-
? "LIKE '%{$search}%'"
372-
: "= '{$search}'";
371+
? "mi.memb___id LIKE '%{$search}%'"
372+
: "mi.memb___id = '{$search}'";
373373
$result = mssql_query("SELECT
374374
mi.memb___id,mi.memb__pwd,mi.bloc_code,mi.country,mi.gender,ms.ConnectStat
375375
FROM dbo.MEMB_INFO AS mi
376376
LEFT JOIN dbo.MEMB_STAT AS ms ON ms.memb___id = mi.memb___id
377-
WHERE mi.memb___id {$queryBuildWhere}");
377+
WHERE {$queryBuildWhere}");
378378

379379
$rank = 1;
380380
while ($row = mssql_fetch_row($result)) {

admin/char.php

Lines changed: 21 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -270,22 +270,34 @@
270270
$search_type = $_POST['search_type'];
271271

272272
$queryBuildWhere = !empty($_POST['search_type'])
273-
? "LIKE '%{$search}%'"
274-
: "= '{$search}'";
275-
$result = mssql_query("SELECT Name,Class,cLevel,{$mmw['reset_column']},strength,dexterity,vitality,energy,accountid,CtlCode FROM dbo.Character WHERE Name {$queryBuildWhere}");
273+
? "c.Name LIKE '%{$search}%'"
274+
: "c.Name = '{$search}'";
275+
$result = mssql_query("SELECT
276+
c.Name,
277+
c.Class,
278+
c.cLevel,
279+
c.{$mmw['reset_column']},
280+
c.Strength,
281+
c.Dexterity,
282+
c.Vitality,
283+
c.Energy,
284+
c.AccountID,
285+
c.CtlCode,
286+
ms.ConnectStat
287+
FROM dbo.Character as c
288+
LEFT JOIN dbo.MEMB_STAT as ms ON ms.memb___id = c.AccountID
289+
WHERE {$queryBuildWhere}
290+
");
276291

277292
$rank = 1;
278293
while ($row = mssql_fetch_row($result)) {
279-
$status_result = mssql_query("SELECT ConnectStat FROM dbo.MEMB_STAT WHERE memb___id='{$row[8]}'");
280-
$status = mssql_fetch_row($status_result);
281-
282-
if ($status[0] == 0) {
294+
if ($row[10] == 0) {
283295
$status = '<img src="../images/offline.gif" alt="offline">';
284296
}
285-
if ($status[0] == 1) {
297+
if ($row[10] == 1) {
286298
$status = '<img src="../images/online.gif" alt="online">';
287299
}
288-
if ($status[0] === null) {
300+
if ($row[10] === null) {
289301
$status = '<img src="../images/death.gif" alt="death">';
290302
}
291303

admin/sqlquery.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
$exampleQuery = "UPDATE table SET [column]=? WHERE [column]=?\n\nSELECT * FROM table WHERE [column]=?\n\nSELECT CAST(Items AS varbinary(1920)) FROM warehouse WHERE AccountID='?'";
77

88
if (isset($_POST['sql_query_true'])) {
9-
$sqlQuery = str_replace(array('\"', '\''), array('"', ''), $_POST['sql_query']);
9+
$sqlQuery = str_replace(array('\"', '\'', '&#39;'), array('"', '', '\''), $_POST['sql_query']);
1010
if ($sqlQueryResult = mssql_query($sqlQuery)) {
1111
$queryResult = $mmw['warning']['green'] . 'Query done!';
1212
writelog('a_sql_query', 'Query: <b>' . $sqlQuery . '</b> Has Been <span style="color:red">Injection</span>');

0 commit comments

Comments
 (0)