Jump to content
  • 0

TOP RITCHEST STATS PROBLEM


Question

Recommended Posts

  • 0
Posted (edited)
On 8/7/2018 at 8:38 PM, .Elfocrash said:

Your query is SQL injectable. Parameterise the parameters properly or else you expose your whole db.

its not.

PDO::ATTR_EMULATE_PREPARES

is always true by default he is using PDO not MySQL driver, plus its a closed code its not inserting data from $_POST or $_GET.

 

but ofc he could bind the data its lazy code tho.

Edited by Nightw0lf
  • 0
Posted
3 minutes ago, Nightw0lf said:

its not.


PDO::ATTR_EMULATE_PREPARES

is always true by default he is using PDO not MySQL driver, plus its a closed code its not inserting data from $_POST or $_GET.

 

but ofc he could bind the data its lazy code tho.

Yeah you're right I realised later it's internal code

  • 0
Posted

Hi. I dont want to create a new topic, so im writing in this one, with the same problem. Im adapting forum into a website and I have a problem with latest date row. I want to add latest post, and i thought i could search for it in database table by MAX command. Is it proper way to whrite sql statement like i am doing?I get that kind of an error: 

Uncaught PDOException: SQLSTATE[21000]: Cardinality violation: 1241 Operand should contain 1 column(s)

Here is my code:

$topic = 'SELECT 
										f.*, 
										u.selected_character,
										(SELECT COUNT(post_entry) number FROM forum_post WHERE post_thread = f.thread_id),
										(SELECT post_user, post_datestamp FROM forum_post WHERE post_thread = f.thread_id AND post_datestamp=(SELECT MAX(post_datestamp) FROM forum_post))
									FROM 
										forum_thread f 
									LEFT JOIN 
										accounts u on f.thread_author = u.id  
									WHERE 
										f.thread_id = :topicid 
									ORDER BY 
										f.thread_lastpost_date'; 
						$topic = $db -> prepare($topic);
						$topic -> bindValue(':topicid', $topic_id, PDO::PARAM_INT); 
						$topic ->execute();
							while($row = $topic -> fetch(PDO::FETCH_OBJ)) { 
								echo"
									<tr>
										<td style='width:5%; text-align:center' class='forumheader2'><img src='../images/forum/nonew.png' alt='' title='' style='border:0' /></td>
										<td style='width:55%' class='forumheader2'><a href='index.php?pages=forum/view_topic&id=".$row->thread_id."'>".$row->thread_name."</a><br />by <a href='forum_viewforum6512.html?11'>".$row->selected_character."</a> » ".ucwords(strftime('%a %b %d %Y, %I:%M%p ', $row->thread_author_date))."</td>
										<td style='width:10%; text-align:center' class='forumheader3'>".$row->number."</td>
										<td style='width:10%; text-align:center' class='forumheader3'>".$row->thread_views."</td>
										<td style='width:20%; text-align:center' class='forumheader3'>
											<span class='smallblacktext'>".$row->post_datestamp."<br />".$row->post_user." <a href='forum_viewtopic4232.html?64400.last'><img src='../images/forum/post2.png' alt='' title='' style='border:0; vertical-align:bottom' /></a></span>
										</td>
									</tr>
									";
							}

 

  • -2
Posted
Just now, wongerlt said:

item_id = 57 AND count > 10 AND owner_id != 1484984 AND owner_id != 1484984

no point for one or two gm  join table.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Perfect way to experience L2 without the brutal official grind. The progression here is so much smoother and faster, you get to the fun PvP and epic raids way quicker. The custom stuff keeps it fresh too. Definitely worth diving into!
    • L2-Getwork server highly customized with high-stats https://l2server.eu/ https://discord.gg/SsVhm7R Rates: L2 High Five fully customized Getwork Style with High Stats and Enchant ExP/Sp: 75x (custom) Drop/Spoil: 1x (custom) Safe: 500 Max: 50 000   Enchant System: Normal Scrolls: 93% - fail - decrease enchant by 20 Blessed Scrolls: 96% - fail - decrease enchant by 10   Armor Max Enchant D-Grade: +1000 Max Enchant C-Grade: +2000 Max Enchant B-Grade: +3000 Max Enchant A-Grade: +4000 Max Enchant S-Grade: +5000   Weapons Max Enchant D-Grade: +5000 Max Enchant C-Grade: +10000 Max Enchant B-Grade: +15000 Max Enchant A-Grade: +20000 Max Enchant S-Grade: +25000 - 50000   Fir Tree Branch (Weapon): +100 into Weapons (max 50 000) Fir Tree Branch (Armor): +15 into Armor (max 5000) Road to Dvc Cloak Enchant: +1 into cloak (max +1000) Masks of Spirit/Demon Horns Enchants: +1 into Masks (max +10) Each accessories has different max enchant and chances Daily Missions (.missions) Collections (ALT + B) Gambling System(.gamble) - each pack cost different amount Gamble Points, different items How to get gambling points? - by killing Raid Bosses/Events or Completing Daily Missions. Clan Bonus VIP Bonuses (maximum level 10) Battlepass (maximum level 100) - by killing monsters Rebirth (starting in Parnassus) Everything in ALT+B Master's Buffs - 100 Small Glass Box (1 buff) Farm Zones: Custom Farm Zones: Ruin of Agony (Exp Zone) Underground Coliseum (Safe Exp Zone) DVC,Brigand,Frost are similiar farm zones with same monsters Dvc Brigand Stronghold Frost Lake Parnassus - TOP ZONE some of our features: .gamble,collections,battlepass,talent tree, rebirth        
    • https://www.mediafire.com/file/l905r1sd84hnovf/FileEdit.rar/file
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock