Sunda Cyber Army


* Sunda Cyber Army 2k17 *
Indonesia Defacer ~


Path : /home/dent/public_html/exams/rafael/
File Upload :
Current File : /home/dent/public_html/exams/rafael/results.php

<?php
$host   = "webdev.iyaserver.com";
$userid = "dent_test";
$userpw = "Acad276_Ttrojan_Dev2Ex@m";
$db     = "dent_exam";

$mysql = new mysqli($host, $userid, $userpw, $db);
if($mysql->connect_errno){
    exit("DB connection error: " . $mysql->connect_error);
}

if(empty($_REQUEST['manufacturer_id']).
empty($_REQUEST['system_id']) .
empty($_REQUEST['type_id'])){
    echo "Please go through the search page. <a href='search.php'>Back</a>";
    exit();
}


$device_name = $_REQUEST['device_name'];
$manufacturer_id = $_REQUEST['manufacturer_id'];
$system_id = $_REQUEST['system_id'];
$type_id = $_REQUEST['type_id'];


$sql = "SELECT d.device_id, d.name, d.price, 
               m.manufacturer, o.system, t.type
        FROM device d
        JOIN make m ON d.manufacturer_id = m.manufacturer_id
        JOIN os o ON d.system_id = o.system_id
        JOIN devicetype t ON d.type_id = t.type_id
        WHERE 1=1";

if ($device_name != "") {
    $sql .= " AND d.name LIKE '%$device_name%'";
}
if ($manufacturer_id != "all") {
    $sql .= " AND d.manufacturer_id = $manufacturer_id";
}
if ($system_id != "all") {
    $sql .= " AND d.system_id = $system_id";
}
if ($type_id != "all") {
    $sql .= " AND d.type_id = $type_id";
}

// always qualify ORDER BY too
$sql .= " ORDER BY d.name";


$results = $mysql->query($sql);
if(!$results){
    echo "SQL error: " . $mysql->error;
    echo "<hr>Your SQL: " . $sql;
    exit();
}
?>
<!DOCTYPE html>

<html>

<head lang="en">

    <meta charset="UTF-8">

    <title>Acad276 Practical Exam: Results</title>

    <style>

        .container {

            width:  600px;

            margin: auto;

        }

        h1 {

            margin: auto;

            text-align: center;

            background-color:   #900;

            color:  #FC0;

            height: 60px;

            line-height: 60px;

        }

        .num-results {

            margin: 20px 10px;

        }

        table {

            margin: auto;

            margin-bottom: 20px;

            width:  80%;

            border-collapse: collapse;

        }

        th, td {

            border: 1px solid #900;

            border-collapse: collapse;

            padding:    10px;

            text-align: center;

        }

        img {

            width: 100px;

        }

        .nav-link{

            margin: 10px 0px;

            font-size: 14px;

        }

    </style>

</head>

<body>

<div class="container">
<h1>Mobile Device Database: Search Results</h1>

<div class="nav-link">
    <a href="search.php">Back to Search Page</a>
</div>

<div class="num-results">
    Your search returned <strong><?php echo $results->num_rows; ?></strong> results.
</div>

<table>
<tr>
    <th>Name</th>
    <th>Price</th>
    <th>Manufacturer</th>
    <th>System</th>
    <th>Type</th>
</tr>

<?php
while($row = $results->fetch_assoc()){
    echo "<tr>";
    echo "<td><a href='details.php?id=" . $row['device_id'] . "'>" . $row['name'] . "</a></td>";
    echo "<td>" . $row['price'] . "</td>";
    echo "<td>" . $row['manufacturer'] . "</td>";
    echo "<td>" . $row['system'] . "</td>";
    echo "<td>" . $row['type'] . "</td>";
    echo "</tr>";
}
?>
</div>

</body>

</html>