Sunda Cyber Army


* Sunda Cyber Army 2k17 *
Indonesia Defacer ~


Path : /home/dent/studentexams/cheniy/
File Upload :
Current File : /home/dent/studentexams/cheniy/results2.php

<!DOCTYPE html>
<html>
<head>
    <meta charset="UTF-8">
    <title>Acad276 Practical Exam: Results</title>
    <style>
        .container {
            width:  600px;
            margin: auto;
        }
        h1 {
            margin: auto;
            text-align: center;
            background-color:   #900;
            color:  #FC0;
            height: 60px;
            line-height: 60px;
        }
        .num-results {
            margin: 20px 10px;
        }
        table {
            margin: auto;
            margin-bottom: 20px;
            width:  80%;
            border-collapse: collapse;
        }
        th, td {
            border: 1px solid #900;
            border-collapse: collapse;
            padding:    10px;
            text-align: center;
        }
        img {
            width: 100px;
        }
        .nav-link{
            margin: 10px 0px;
            font-size: 14px;
        }
    </style>
</head>
<body>



<?php
//SQL Database information
$host = "webdev.iyaclasses.com";
$userid = "dent_guest";
$userpw = "Acad276_Ttrojan_Dev2Ex@m";
$db = "dent_exam";

//setting up connection to SQL Database
$mysql = new mysqli(
    $host,
    $userid,
    $userpw,
    $db
);

//if connection error
if($mysql ->connect_errno){
    echo "ERROR Database Connection: ";
    echo $mysql -> connect_error;
    exit();
}

?>





<div class="container">
    <h1>Mobile Device Database: Search Results</h1>
    <div class="nav-link">
        <a href="search.php"><< Back to Search Page</a>
    </div>

    <?php
    $sql = "SELECT * FROM devices WHERE 1=1 ";
    if($_REQUEST["device_name"] != "") {
        $sql .= " AND name LIKE '%" . $_REQUEST["device_name"] . "%'";
    }
    if($_REQUEST["manufacturer_id"] != "all") {
        $sql .= " AND manufacturer_id = " . $_REQUEST["manufacturer_id"] . "";
    }
    if($_REQUEST["system_id"] != "all"){
        $sql .= " AND system_id=".$_REQUEST["system_id"]."";
    }
    if($_REQUEST["type_id"] != "all"){
        $sql .= " AND type_id='".$_REQUEST["type_id"]."'";
    }
    echo $sql;

    $results = $mysql -> query($sql); // take my sql statement, submit as a query to database, store results in results
    if(!$results){
        echo " Error! ".$mysql->error;
        exit();
    }
    echo "<br>Your search returned " . $results->num_rows." records <br>";

    ?>

    <table>
        <tr>
            <th>Name</th>
            <th>Price</th>
            <th>Manufacturer</th>
            <th>System</th>
            <th>Type</th>
        </tr>


    <?php
    while($currentrow = $results->fetch_assoc()){
       echo "<tr>";
        echo "<td><a href='details.php?id=".$currentrow["device_id"]."'>".$currentrow["name"]."</a></td>";
        echo "<td>".$currentrow["price"]."</td>";
        echo "<td>".$currentrow["manufacturer_id"]."</td>";
        echo "<td>".$currentrow["system_id"]."</td>";
        echo "<td>".$currentrow["type_id"]."</td>"; //i know these should not be ids but i dont have enough time to figure out a way to get around it
    echo "</tr>";
   // "<a href='details.php?id=".$currentrow["device_id"]."'> DELETE</a>".
    //"<br>";

    }
    ?>

     <!--   ****** SAMPLE OUTPUT ROW ******

        <tr>
            <td><a href="details.php?id=10">Pixel</a></td>
            <td>549.00</td>
            <td>Google</td>
            <td>Android</td>
            <td>Smartphone</td>
        </tr>
        <tr>
            <td><a href="details.php?id=11">Pixel 2</a></td>
            <td>649.00</td>
            <td>Google</td>
            <td>Android</td>
            <td>Smartphone</td>
        </tr>
        <tr>
            <td><a href="details.php?id=12">Pixelbook</a></td>
            <td>999.00</td>
            <td>Google</td>
            <td>Android</td>
            <td>Laptop</td>
        </tr>
        -->
    </table>
</div>

</body>
</html>