Файл: install/inc/3.php
Строк: 80
<?
if (isset($_POST['reg']))
{
$db=mysql_connect($_SESSION['host'], $_SESSION['user'],$_SESSION['pass']);
mysql_select_db($_SESSION['db'],$db);
mysql_query('set charset utf8');
mysql_query('SET names utf8');
mysql_query('set character_set_client="utf8"');
mysql_query('set character_set_connection="utf8"');
mysql_query('set character_set_result="utf8"');
$tmp_set['title']=strtoupper($_SERVER['HTTP_HOST']).' - Главная';
$tmp_set['mysql_host']=$_SESSION['host'];
$tmp_set['mysql_user']=$_SESSION['user'];
$tmp_set['mysql_pass']=$_SESSION['pass'];
$tmp_set['mysql_db_name']=$_SESSION['db'];
if (empty($err))
{
$nick = mysql_real_escape_string($_POST[nick]);
$password = mysql_real_escape_string($_POST[password]);
$dbfile = "<?n
/* Скрипт хостинга картинокn
Автор: romanvht n
roman.vkostin@gmail.com */n
$db_host = 'localhost';n
$db_user = '$_SESSION[user]';n
$db_pass = '$_SESSION[pass]';n
$db_name = '$_SESSION[db]';n
$db = new mysqli($db_host, $db_user, $db_pass, $db_name);n
if (mysqli_connect_errno()) {n
printf('Нет подключения к бд: %s\n', mysqli_connect_error());n
exit();n
}n
$db->set_charset('utf8');n
// Логин и пароль админаn
$admlogin = $nick;n
$admpass = md5(sha1('$password'));n
//n
?>";
if (!file_put_contents('../inc/db.php', $dbfile)) {
echo 'ERROR: Can not write db.php</body></html>';
exit;
}
$_SESSION['admin'] = 1;
setcookie("admlogin", $nick, time()+9999999);
setcookie("admpass", $password, time()+9999999);
echo 'Установка окончена. Удалите папку INSTALL<br/><a href="/">На сайт</a>';
exit;
}
}
if (isset($err))
{
foreach ($err as $key=>$value) {
echo "<div class='err'>$value</div>n";
}
echo "<hr />n";
}
echo "<form action='index.php?$passgen' method='post'>n";
echo "Логин (3-16 символов):<br />n<input type='text' name='nick'".((isset($nick))?" value='".$nick."'":" value='ADMIN'")." maxlength='16' /><br />n";
echo "Пароль (6-16 символов):<br />n<input type='password'".((isset($password))?" value='".$password."'":null)." name='password' maxlength='16' /><br />n";
echo "<input type='submit' name='reg' value='Регистрация' /><br />n";
echo "</form>n";
echo "<hr />n";
echo "<b>Шаг: $_SESSION[i_step]</b> из <b>4</b>n";
?>