Sunda Cyber Army


* Sunda Cyber Army 2k17 *
Indonesia Defacer ~


Path : /home/dent/public_html/exams/maxine/
File Upload :
Current File : /home/dent/public_html/exams/maxine/results_exam.php

<?php

if(empty($_REQUEST['manufacturer_id'])) {
    echo "Please go through search page. (or redirect)";
    header('Location: search_exam.php');
    exit();
}


$host = "webdev.iyaserver.com";
$userid = "dent_test";
$userpw = "Acad276_Ttrojan_Dev2Ex@m";
$db = "dent_exam";

//include '../pdloginvariables.php';

$mysql = new mysqli(
    $host,
    $userid,
    $userpw,
    $db
);

if($mysql->connect_errno) {
    echo "db connection error : " . $mysql->connect_error;
    exit();
}
?>

<!DOCTYPE html>

<html>

<head lang="en">

    <meta charset="UTF-8">

    <title>Acad276 Practical Exam: Results</title>

    <style>

        .container {

            width:  600px;

            margin: auto;

        }

        h1 {

            margin: auto;

            text-align: center;

            background-color:   #900;

            color:  #FC0;

            height: 60px;

            line-height: 60px;

        }

        .num-results {

            margin: 20px 10px;

        }

        table {

            margin: auto;

            margin-bottom: 20px;

            width:  80%;

            border-collapse: collapse;

        }

        th, td {

            border: 1px solid #900;

            border-collapse: collapse;

            padding:    10px;

            text-align: center;

        }

        img {

            width: 100px;

        }

        .nav-link{

            margin: 10px 0px;

            font-size: 14px;

        }

    </style>

</head>

<body>

<div class="container">

    <h1>Mobile Device Database: Search Results</h1>
    <div class="nav-link">

        <a href="search_exam.php"><< Back to Search Page</a>

    </div>

    <?php
        $sql = 		"SELECT device.name, device.price, device.manufacturer_id, device.system_id, device.type_id  
                        FROM device, make, devicetype, os 
                        WHERE 
                            device.manufacturer_id = make.manufacturer_id
                            AND
                            device.system_id = os.system_id
                            AND
                            device.type_id = devicetype.type_id";

        if($_REQUEST['manufacturer_id'] != "All") {

            $sql .= " AND manufacturer = '" . $_REQUEST['manufacturer_id'] ."'";
        }

        if($_REQUEST['system_id'] != "All") {
            $sql .= " AND system ='" . $_REQUEST["system_id"] . "'";
        }

        if($_REQUEST['type_id'] != "All") {
            $sql .=		" AND type = '" . $_REQUEST["type_id"] . "'";
        }
        // $sql .= " ORDER BY ". $_REQUEST['orderby'];

        $results = $mysql->query($sql);

        if(!$results) {
            echo "<hr>Your SQL:<br> " . $sql . "<br><br>";
            echo "SQL Error: " . $mysql->error . "<hr>";
            exit();
        }


        echo "<div class='num-results'>" . "Your search returned <strong>" .
            $results->num_rows .
        "</strong> results. </div>";

echo $sql;



    echo "<table>

        <tr>

            <th>Name</th>

            <th>Price</th>

            <th>Manufacturer</th>

            <th>System</th>

            <th>Type</th>

        </tr>
        

        <tr>";

            while($currentrow = $results->fetch_assoc()) {
                echo "<td><a href='details_exam.php?id=" .
                    $currentrow['name'] .
                    "'> </a></td>" .

                    "<td>" . $currentrow['price'] . "</td>" .

                    "<td>" . $currentrow['manufacturer_id'] . "</td>" .

                    "<td>" . $currentrow['system_id'] . "</td>" .

                    "<td>" . $currentrow['type_id'] . "</td> </tr> </table>" .

                    "</div>" .
                    "<br style='clear:both;'>";
}
?>
</div>

</body>

</html>