C:\Program Files (x86)\Apache Software Foundation\Apache2.2\htdocs\rodam\administrator\index.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
<?php
/**
* @version $Id: index.php 2599 2006-02-24 07:49:49Z stingrey $
* @package Joomla
* @copyright Copyright (C) 2005 Open Source Matters. All rights reserved.
* @license http://www.gnu.org/copyleft/gpl.html GNU/GPL, see LICENSE.php
* Joomla! is free software. This version may have been modified pursuant
* to the GNU General Public License, and as distributed it includes or
* is derivative of works licensed under the GNU General Public License or
* other free or open source software licenses.
* See COPYRIGHT.php for copyright notices and details.
*/

// Set flag that this is a parent file
define'_VALID_MOS');

if (!
file_exists'../configuration.php' )) {
    
header'Location: ../installation/index.php' );
    exit();
}

require_once( 
'../configuration.php' );
require_once( 
'../includes/joomla.php' );
include_once ( 
$mosConfig_absolute_path '/language/'$mosConfig_lang .'.php' );

//Installation sub folder check, removed for work with SVN
if (file_exists'../installation/index.php' )) {
    
define'_INSTALL_CHECK');
    include (
'../offline.php');
    exit();
}

$option mosGetParam$_REQUEST'option'NULL );

// mainframe is an API workhorse, lots of 'core' interaction routines
$mainframe = new mosMainFrame$database$option'..'true );

if (isset( 
$_POST['submit'] )) {
    
/** escape and trim to minimise injection of malicious sql */
    
$usrname     $database->getEscapedmosGetParam$_POST'usrname''' ) );
    
$pass         $database->getEscapedmosGetParam$_POST'pass''' ) );

    if (!
$pass) {
        echo 
"<script>alert('Please enter a password'); document.location.href='index.php';</script>\n";
    } else {
        
$pass md5$pass );
    }

    
$query "SELECT COUNT(*)"
    
"\n FROM #__users"
    
"\n WHERE ("
    
// Administrators
    
"\n gid = 24"
    
// Super Administrators
    
"\n OR gid = 25"
    
"\n )"
    
;
    
$database->setQuery$query );
    
$count intval$database->loadResult() );
    if (
$count 1) {
        
mosErrorAlert_LOGIN_NOADMINS );
    }

    
$my null;
    
$query "SELECT *"
    
"\n FROM #__users"
    
"\n WHERE username = '$usrname'"
    
"\n AND password = '$pass'"
    
"\n AND block = 0"
    
;
    
$database->setQuery$query );
    
$database->loadObject$my );

    
/** find the user group (or groups in the future) */
    
if (@$my->id) {
        
$grp             $acl->getAroGroup$my->id );
        
$my->gid         $grp->group_id;
        
$my->usertype     $grp->name;

        if ( 
strcmp$my->password$pass ) || !$acl->acl_check'administration''login''users'$my->usertype ) ) {
            
mosErrorAlert("Incorrect Username, Password, or Access Level.  Please try again""document.location.href='index.php'");
        }

        
session_namemd5$mosConfig_live_site ) );
        
session_start();

        
$logintime     time();
        
$session_id md5$my->id $my->username $my->usertype $logintime );
        
$query "INSERT INTO #__session"
        
"\n SET time = '$logintime', session_id = '$session_id', userid = $my->id, usertype = '$my->usertype', username = '$my->username'"
        
;
        
$database->setQuery$query );
        if (!
$database->query()) {
            echo 
$database->stderr();
        }

        
$_SESSION['session_id']         = $session_id;
        
$_SESSION['session_user_id']     = $my->id;
        
$_SESSION['session_username']     = $my->username;
        
$_SESSION['session_usertype']     = $my->usertype;
        
$_SESSION['session_gid']         = $my->gid;
        
$_SESSION['session_logintime']     = $logintime;
        
$_SESSION['session_user_params']= $my->params;
        
$_SESSION['session_userstate']     = array();

        
session_write_close();
        
/** cannot using mosredirect as this stuffs up the cookie in IIS */
        
echo "<script>document.location.href='index2.php';</script>\n";
        exit();
    } else {
        
mosErrorAlert("Incorrect Username, Password.  Please try again""document.location.href='index.php'");
    }
} else {
    
initGzip();
    
$path $mosConfig_absolute_path '/administrator/templates/' $mainframe->getTemplate() . '/login.php';
    require_once( 
$path );
    
doGzip();
}
?>