vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 Programming Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=15)
-   -   Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource (https://vborg.vbsupport.ru/showthread.php?t=189480)

buddhabadboy 08-29-2008 05:01 PM

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource
 
Hello all,
I hope I'm putting this in the right Forum.
I'm a Systems Admin, that's trying to modify some existing php code in the plugin system (register_addmember_process)

We have a proccess that needs to verify a few options for a user to have access to the boards. Whenever I put in this new modified code, I get this:

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /register.php(358) : eval()'d code on line 30

Can anyone help? here's the code I put in:

$aff_db_name = "xxx";
$aff_db_user = "xxx";
$aff_db_pass = "xxx";
$aff_db_host = "xxx";
$vip_username = $vbulletin->GPC['username'];
$vip_pass = $_REQUEST["pss"];
$dbconn = mysql_connect($aff_db_host, $aff_db_user, $aff_db_pass);
if (!$dbconn) {
die ('Could not connect: ' . mysql_error());
}
mysql_select_db($aff_db_name, $dbconn);

$query = "SELECT email, password, passcode FROM vippass WHERE passcode='$vip_username' AND password ='$vip_pass'";
$query1 = "SELECT * FROM vipmember WHERE passcode='$vip_username'";
$query2 = "SELECT * FROM transaction WHERE transtype='SALE' AND passcode='$vip_username' AND date >= DATE_SUB(CURDATE(),INTERVAL 90 DAY)";
$result = mysql_query($query, $dbconn);
$result1 = mysql_query($query1, $dbconn);
$result2 = mysql_query($query2, $dbconn);

if (mysql_num_rows($result) >= 1 AND mysql_num_rows($result1) >= 1) {
$row = mysql_fetch_assoc($result);
$userdata->set('email',$row['email']);
}
elseif (mysql_num_rows($result) >= 1 AND mysql_num_rows($result2) >= 1) {
$row = mysql_fetch_assoc($result);
$userdata->set('email',$row['email']);
}
else {
eval(standard_error("The User Name or Password did not match, or not VIP Member."));
}
mysql_close($dbconn);

MoT3rror 08-29-2008 07:17 PM

You should use the inbuilt db functions for one. Second your code doesn't protect against sql injection.

Here is some links for it

Escaping
The unexpected Sql Injection

When you start using the vbulletin db functions, your page will come up with a db error if there is one which is probably why you are getting that code.

Dismounted 08-30-2008 05:53 AM

Also see this article.

buddhabadboy 09-02-2008 02:58 PM

thanks for the warning, but the forum isn't a major one of ours, so we're not all that worried about sql injection. Also, the information we get as a condition for registration deals with a different database.

Is there any way to know what is causing this problem? OR, better yet, is there any way i can "pass" the results of:

mysql_num_rows($result2) AND $result2

on the return page, so i can see what is going on? (log file??)

thanks!

MoT3rror 09-02-2008 07:17 PM

Like I said you are getting a database error. Use mysql_error(); to get the error text.


All times are GMT. The time now is 05:30 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01219 seconds
  • Memory Usage 1,718KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (5)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete