HEX
Server: Apache
System: Linux cpanel91.fastsecurehost.com 3.10.0-962.3.2.lve1.5.87.el7.x86_64 #1 SMP Tue Jan 28 09:38:56 UTC 2025 x86_64
User: harmonyg (1050)
PHP: 8.2.29
Disabled: shell, shell_exec, exec, ini_alter, dl, show_source, passthru, system, eval, pfsockopen, leak, apache_child_terminate, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid
Upload Files
File: /home/harmonyg/www/classes/login.php
<?php
class login extends ACore {
	
	
	protected function obr() {
		$login = strip_tags(mysql_real_escape_string($_POST['login']));
		$password = strip_tags(mysql_real_escape_string($_POST['password']));
		
		if(!empty($login) AND !empty($password)) {
			$password = md5($password);
			
			$query = "SELECT id FROM users WHERE login='$login' AND password = '$password'";
			
			$result = mysql_query($query);
			
			if(!$result) {
				exit(mysql_error());
			} 
			
			if(mysql_num_rows($result) == 1) {
				$_SESSION['user'] = TRUE;
				header("Location:?option=admin");
				exit();
			}
			else {
				exit("No user");
			}
			
		}
		else {
			exit("Empty fields");
		}
	}
	
	
	public function get_content() {
		
		echo '<div id="main">';
		
print <<<HEREDOC
<form enctype='multipart/form-data' action='' method='POST'>
<p>Login:<br />
<input type='text' name='login'>
</p>

<p>Password:<br />
<input type='password' name='password'>
</p>
<p><input type='submit' name='button' value='Save'></p></form>
HEREDOC;
	}
}
?>