buy.php
PHP Code:
$selectitem = "SELECT * FROM shop_tbl WHERE item_id = '".$_GET['a']."'";
login.php
PHP Code:
$ss = "SELECT * FROM ACCOUNT_TBL WHERE account = '".$_POST['account']."' and password = '$pass'";
news.php
PHP Code:
$news = "SELECT * FROM news_tbl WHERE id = '".$_GET['id']."'";
$newsa = "SELECT * FROM news_tbl WHERE id = '".$_GET['id']."'";
register.php
PHP Code:
$user = "SELECT * FROM ACCOUNT_TBL WHERE account = '".$_POST['account']."'";
$insert1 = "INSERT INTO ACCOUNT_TBL(account, password, isuse, member, id_no1, id_no2, realname, email, registerdate) VALUES ('".$_POST['account']."', '$md5ss', 'T', 'A', 'a00000', '".$_POST['id_no2']."', '', '".$_POST['email']."".$_POST['select']."', '$date')";
$insert2 = "INSERT INTO ACCOUNT_TBL_DETAIL(account, gamecode, tester, m_chLoginAuthority, regdate, BlockTime, EndTime, WebTime, isuse) VALUES ('".$_POST['account']."', 'A000', '2', 'F', '$time', '20060101', '20501231', '20060101', 'T')";
shop.php
PHP Code:
$character = "SELECT * FROM CHARACTER_TBL WHERE m_szName = '".$_POST['select']."'";
shopde.php
PHP Code:
$shopde = "SELECT * FROM shop_tbl WHERE item_id = '".$_GET['id']."'";
user.php
PHP Code:
$updateaccount = "UPDATE ACCOUNT_TBL set password = '$md52', id_no2 = '".$_POST['id_no2']."', email = '".$_POST['email']."' WHERE account = '$account'";
$chpassde = "UPDATE ACCOUNT_TBL set id_no2 = '".$_POST['id_no2']."' WHERE account = '$account'";
$updateguild = "UPDATE CHARACTER_TBL set m_tGuildMember = '' WHERE m_szName = '".$_POST['list']."'";
admin/home.php
PHP Code:
$login = "SELECT * FROM admin_tbl WHERE username = '".$_POST['username']."' and password = '".$_POST['password']."'";
$news = "INSERT INTO news_tbl(title,description,category,date) VALUES('".$_POST['title']."','".$_POST['text']."','".$_POST['category']."','$date')";
$getnews = "SELECT * FROM news_tbl WHERE id = '".$_GET['id']."'";
$updatenews = "UPDATE news_tbl SET title = '".$_POST['title']."', description = '".$_POST['text']."', category = '".$_POST['category']."' WHERE id = '".$editnfetch['id']."'";
$addslider = "INSERT INTO sliders_tbl(name,images,link) VALUES('".$_POST['name']."','".$_POST['images']."','".$_POST['link']."')";
$getslider = "SELECT * FROM sliders_tbl WHERE id = '".$_GET['id']."'";
$updatesliders = "UPDATE sliders_tbl SET name = '".$_POST['name']."', images = '".$_POST['images']."',link = '".$_POST['link']."' WHERE id = '".$_POST['id']."'";
$updatemalls = "UPDATE shop_tbl SET item_id = '".$_POST['item_id']."', item_name = '".$_POST['item_name']."', item_description = '".$_POST['item_description']."', item_count = '".$_POST['item_count']."', item_Ability = '".$_POST['item_Ability']."', img_type = '".$_POST['img_type']."', price = '".$_POST['price']."', promotion = '".$_POST['promotion']."', catagory = '".$_POST['catalog']."' WHERE id = '".$_POST['id']."'";
$insertmall = "INSERT INTO shop_tbl(item_id,item_name,item_description,item_count,item_Ability,img_type,price,promotion,catagory) VALUES('".$_POST['item_id']."','".$_POST['item_name']."','".$_POST['item_description']."','".$_POST['item_count']."','".$_POST['item_Ability']."','".$_POST['img_type']."','".$_POST['price']."','".$_POST['promotion']."','".$_POST['catalog']."')";
END
Count : 21
SQL Injection?