* Sunda Cyber Army 2k17 *
Indonesia Defacer ~
<?php
if(!$_REQUEST['manufacturer_id'] || !$_REQUEST['system_id'] || !$_REQUEST['type_id']){
exit("ERROR LEAVE PAGE VALUES MISSING");
};
$mysql = new mysqli (
"webdev.iyaclasses.com",
"dent_guest",
"Acad276_Ttrojan_Dev2Ex@m",
"dent_exam"
);
if($mysql->connect_errno) {
echo "db connection error : " . $mysql->connect_error;
exit();
};
$sql = "SELECT device_id, manufacturer, price, name, system, type FROM manufacturers, devices, systems, types WHERE devices.system_id = systems.system_id AND devices.manufacturer_id = manufacturers.manufacturer_id AND devices.type_id = types.type_id";
if($_REQUEST['manufacturer_id'] != "all"){
$manufacturer = " AND manufacturer='" . $_REQUEST['manufacturer_id'] . "'";
} else{
$manufacturer = "";
}
if($_REQUEST['system_id'] != "all"){
$system = " AND system='" . $_REQUEST['system_id'] ."'";
} else{
$system = "";
}
if($_REQUEST['type_id'] != "all"){
$type = " AND type='" . $_REQUEST['type_id'] . "'";
} else{
$type = "";
}
if($_REQUEST['device_name']){
$name = " AND name LIKE '%" . $_REQUEST['device_name'] . "%'";
}
$sql .= $manufacturer . $type . $system . $name;
$results = $mysql->query($sql);
if(!$results) {
echo "SQL Error: " . $mysql->error;
exit();
};
?>
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>Acad276 Practical Exam: Results</title>
<style>
.container {
width: 600px;
margin: auto;
}
h1 {
margin: auto;
text-align: center;
background-color: #900;
color: #FC0;
height: 60px;
line-height: 60px;
}
.num-results {
margin: 20px 10px;
}
table {
margin: auto;
margin-bottom: 20px;
width: 80%;
border-collapse: collapse;
}
th, td {
border: 1px solid #900;
border-collapse: collapse;
padding: 10px;
text-align: center;
}
img {
width: 100px;
}
.nav-link{
margin: 10px 0px;
font-size: 14px;
}
</style>
</head>
<body>
<div class="container">
<h1>Mobile Device Database: Search Results</h1>
<div class="nav-link">
<a href="search.php"><< Back to Search Page</a>
</div>
<div class="num-results">
<?php echo "Your search found " . $results->num_rows . " records"; ?>
</div>
<table>
<tr>
<th>Name</th>
<th>Price</th>
<th>Manufacturer</th>
<th>System</th>
<th>Type</th>
</tr>
<!--
****** SAMPLE OUTPUT ROW ******
-->
<?php
while($currentrow = $results->fetch_assoc()){
echo "<tr>";
echo "<td><a href='details.php?id=" . $currentrow['device_id'] . "'>". $currentrow['name'] ."</a></td>";
echo "<td>". $currentrow['price'] . "</td>";
echo "<td>". $currentrow['manufacturer'] . "</td>";
echo "<td>". $currentrow['system'] . "</td>";
echo "<td>". $currentrow['type'] . "</td>";
echo "</tr>";
}
?>
</table>
</div>
</body>
</html>