File Manager V1.5

[SYSTEM@ROOT]: /home/ketechno/public_html/QuickCheck/
INJECT_FILE:
NEW_ENTRY:

FILE_CONTENT: register.php

<?php
require_once('db_conn.php');
session_start();
 $surname	= ( isset( $_REQUEST['surname'] ) )? 		$_REQUEST['surname']: null;
$firstname	= ( isset( $_REQUEST['firstname'] ) )? 		$_REQUEST['firstname']: null;   
$email	= ( isset( $_REQUEST['email'] ) )? 		        $_REQUEST['email']: null;
$password	= ( isset( $_REQUEST['password'] ) )? 		$_REQUEST['password']: null;
$cluster	= ( isset( $_REQUEST['cluster'] ) )? 		$_REQUEST['cluster']: null;
$id2 = 0;
  //print_r($_REQUEST);
$sql = "INSERT INTO user (id2, surname, firstname, email, password, cluster)
 VALUES ('$id2','$surname','$firstname','$email','$password','$cluster')";

if ($conn->multi_query($sql) === TRUE) {
	
	$result = mysqli_query($conn,"SELECT * FROM user where email = '".$email."' and password = '".$password."'");
	$message = mysqli_num_rows($result);
	if ($message != '0'){
	while($row = mysqli_fetch_array($result)){
	$_SESSION['firstname'] = $row['firstname'];
	$_SESSION['surname'] = $row['surname'];
	$_SESSION['id'] = $row['id'];
	$_SESSION['id2'] = $row['id2'];
	$_SESSION['cluster'] = $row['cluster'];
	
	} }
	
	echo ("<SCRIPT LANGUAGE='JavaScript'>
   
    window.location.href='create.php';
    </SCRIPT>");
	
	  
 }
else {
  
	echo ("<SCRIPT LANGUAGE='JavaScript'>
    window.alert('Error  Registeration Failed try again')
    window.location.href='index.php';
    </SCRIPT>");
}

 
$conn->close();

?> 
[ KEMBALI ]