JohnCMSMod tin nhắn nhanh for johncms

3 bài đăng
04.10.2017 / 14:07
Hoccode
Bài đăng: 65
Member
trym.tk

Lâu lâu rảnh share :)

dán đâu cũng oki. Head.php chẳng hạn

PHP
  1. //////--------JOHNCMS MAIL FASTER-------////////////
  2. $tinnhan = mysql_fetch_assoc(mysql_query("select * FROM `cms_mail` WHERE `from_id`='$user_id' AND `read`='0' AND `sys`='0' AND `delete`!='$user_id' ORDER BY `time` ASC LIMIT 1"));
  3.  
  4. if ($_POST['tn']) {
  5. echo ''.$nickgui['id'].'';
  6. mysql_query("insert into `cms_mail` set
  7. `user_id` = '" . $datauser['id'] . "',
  8. `from_id` = '" . $_POST['gui'] . "',
  9. `text` = '" . mysql_real_escape_string($_POST['text']) . "',
  10. `time` = '" . time() . "'");
  11. echo '<script type="text/javascript" language="javascript">
  12.  
  13. function refreshPage()
  14. {
  15. location.reload(true);
  16. }
  17.  
  18. </script>';
  19.  
  20. }
  21.  
  22.  
  23. $idtin = '' .$tinnhan['id']. '';
  24.  
  25. $nickgui = mysql_fetch_assoc(mysql_query("select * from `users` where `id`='" . $tinnhan['user_id'] . "'"));
  26.  
  27.  
  28. $new_maila = mysql_result(mysql_query("SELECT COUNT(*) FROM `cms_mail` WHERE `from_id`='$user_id' AND `read`='0' AND `sys`='0' AND `delete`!='$user_id'"), 0);
  29.  
  30.  
  31. $textm = $tinnhan['text'];
  32. $textm = bbcode::tags($textm);
  33. $textm = functions::smileys($textm, 1);
  34.  
  35.  
  36. if ($new_maila >= 1) echo '<div style="color: #333333;
  37. border: 1px solid #a1a1a1;
  38. background-color: #fff5bc;
  39. margin: 4px 0px 0px 0px;
  40. padding: 2px 4px 2px 4px;"><b>'.$nickgui['name'].'</b> : ' . $textm . '
  41. <form name="post" method="post"><input type="text" value="" name="text"><input type="hidden" value="'.$tinnhan['user_id'].'" name="gui"><input class="button" type="submit" name="tn" value="Gửi"/></form></div>';
  42.  
  43.  
  44. mysql_query("update `cms_mail` set `read`='1' where `id`='" . $idtin . "';");
  45.  
  46.  
  47. //////---------End Tin Nhan By Clombies123-------////////////
04.10.2017 / 14:14
MrKen
Bài đăng: 2643
Trùm!
Vẫn là A N H

injection kìa :D

04.10.2017 / 14:15
Hoccode
Bài đăng: 65
Member
trym.tk
MrKen đã viết

injection kìa :D

Biết thì add function check vô :)