C:\Program Files (x86)\Apache Software Foundation\Apache2.2\htdocs\netspot\administrator\index.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
<?php
/**
* @version $Id: index.php,v 1.6 2005/02/13 02:41:39 stingrey Exp $
* @package Mambo
* @copyright (C) 2000 - 2005 Miro International Pty Ltd
* @license http://www.gnu.org/copyleft/gpl.html GNU/GPL
* Mambo is Free Software
*/

/** Set flag that this is a parent file */
define"_VALID_MOS");

if (!
file_exists'../configuration.php' )) {
    
header'Location: ../installation/index.php' );
    exit();
}

require_once( 
'../configuration.php' );
require_once( 
'../includes/mambo.php' );
include_once ( 
$mosConfig_absolute_path .'/language/'$mosConfig_lang .'.php' );
$database = new database$mosConfig_host$mosConfig_user$mosConfig_password$mosConfig_db$mosConfig_dbprefix );
$database->debug$mosConfig_debug );
$acl = new gacl_api();

$option mosGetParam$_REQUEST'option'NULL );

// mainframe is an API workhorse, lots of 'core' interaction routines
$mainframe = new mosMainFrame$database$option'..'true );

if (isset( 
$_POST['submit'] )) {
    
/** escape and trim to minimise injection of malicious sql */
    
$usrname     $database->getEscapedtrimmosGetParam$_POST'usrname''' ) ) );
    
$pass         $database->getEscapedtrimmosGetParam$_POST'pass''' ) ) );

    if (!
$pass) {
        echo 
"<script>alert('Please enter a password'); document.location.href='index.php';</script>\n";
    } else {
        
$pass md5$pass );
    }

    
$query "SELECT COUNT(*)"
    
"\n FROM #__users"
    
"\n WHERE ( LOWER( usertype ) = 'administrator'" 
    
"\n OR LOWER( usertype ) = 'superadministrator'"
    
"\n OR LOWER( usertype ) = 'super administrator' )"
    
;
    
$database->setQuery$query );
    
$count intval$database->loadResult() );
    if (
$count 1) {
        echo 
"<script>alert(\""._LOGIN_NOADMINS."\"); window.history.go(-1); </script>\n";
        exit();
    }
    
    
$query "SELECT * FROM #__users WHERE username='$usrname' AND block='0'";
    
$database->setQuery$query );
    
$my null;
    
$database->loadObject$my );

    
/** find the user group (or groups in the future) */
    
$grp             $acl->getAroGroup$my->id );
    
$my->gid         $grp->group_id;
    
$my->usertype     $grp->name;

    if (
$my->id) {
        if (
strcmp$my->password$pass )
        || !
$acl->acl_check'administration''login''users'$my->usertype )) {
            echo 
"<script>alert('Incorrect Username, Password, or Access Level.  Please try again'); document.location.href='index.php';</script>\n";
            exit();
        }

        
session_name'mosadmin' );
        
session_start();

        
$logintime     time();
        
$session_id md5"$my->id$my->username$my->usertype$logintime);
        
$query "INSERT INTO #__session"
        
"\nSET time='$logintime', session_id='$session_id', "
        
"userid='$my->id', usertype='$my->usertype', username='$my->username'"
        
;
        
$database->setQuery$query );
        if (!
$database->query()) {
            echo 
$database->stderr();
        }

        
$_SESSION['session_id']         = $session_id;
        
$_SESSION['session_user_id']     = $my->id;
        
$_SESSION['session_username']     = $my->username;
        
$_SESSION['session_usertype']     = $my->usertype;
        
$_SESSION['session_gid']         = $my->gid;
        
$_SESSION['session_logintime']     = $logintime;
        
$_SESSION['session_userstate']     = array();

        
session_write_close();
        
/** cannot using mosredirect as this stuffs up the cookie in IIS */
        
echo "<script>document.location.href='index2.php';</script>\n";
        exit();
    } else {
        echo 
"<script>alert('Incorrect Username and Password, please try again'); document.location.href='index.php';</script>\n";
        exit();
    }
} else {
    
initGzip();
    
$path $mosConfig_absolute_path '/administrator/templates/' $mainframe->getTemplate() . '/login.php';
    require_once( 
$path );
    
doGzip();
}
?>