Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 Programming Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-29-2008, 05:01 PM
buddhabadboy buddhabadboy is offline
 
Join Date: Aug 2008
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource

Hello all,
I hope I'm putting this in the right Forum.
I'm a Systems Admin, that's trying to modify some existing php code in the plugin system (register_addmember_process)

We have a proccess that needs to verify a few options for a user to have access to the boards. Whenever I put in this new modified code, I get this:

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /register.php(358) : eval()'d code on line 30

Can anyone help? here's the code I put in:

$aff_db_name = "xxx";
$aff_db_user = "xxx";
$aff_db_pass = "xxx";
$aff_db_host = "xxx";
$vip_username = $vbulletin->GPC['username'];
$vip_pass = $_REQUEST["pss"];
$dbconn = mysql_connect($aff_db_host, $aff_db_user, $aff_db_pass);
if (!$dbconn) {
die ('Could not connect: ' . mysql_error());
}
mysql_select_db($aff_db_name, $dbconn);

$query = "SELECT email, password, passcode FROM vippass WHERE passcode='$vip_username' AND password ='$vip_pass'";
$query1 = "SELECT * FROM vipmember WHERE passcode='$vip_username'";
$query2 = "SELECT * FROM transaction WHERE transtype='SALE' AND passcode='$vip_username' AND date >= DATE_SUB(CURDATE(),INTERVAL 90 DAY)";
$result = mysql_query($query, $dbconn);
$result1 = mysql_query($query1, $dbconn);
$result2 = mysql_query($query2, $dbconn);

if (mysql_num_rows($result) >= 1 AND mysql_num_rows($result1) >= 1) {
$row = mysql_fetch_assoc($result);
$userdata->set('email',$row['email']);
}
elseif (mysql_num_rows($result) >= 1 AND mysql_num_rows($result2) >= 1) {
$row = mysql_fetch_assoc($result);
$userdata->set('email',$row['email']);
}
else {
eval(standard_error("The User Name or Password did not match, or not VIP Member."));
}
mysql_close($dbconn);
Reply With Quote
  #2  
Old 08-29-2008, 07:17 PM
MoT3rror MoT3rror is offline
 
Join Date: Mar 2007
Posts: 423
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You should use the inbuilt db functions for one. Second your code doesn't protect against sql injection.

Here is some links for it

Escaping
The unexpected Sql Injection

When you start using the vbulletin db functions, your page will come up with a db error if there is one which is probably why you are getting that code.
Reply With Quote
  #3  
Old 08-30-2008, 05:53 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Also see this article.
Reply With Quote
  #4  
Old 09-02-2008, 02:58 PM
buddhabadboy buddhabadboy is offline
 
Join Date: Aug 2008
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

thanks for the warning, but the forum isn't a major one of ours, so we're not all that worried about sql injection. Also, the information we get as a condition for registration deals with a different database.

Is there any way to know what is causing this problem? OR, better yet, is there any way i can "pass" the results of:

mysql_num_rows($result2) AND $result2

on the return page, so i can see what is going on? (log file??)

thanks!
Reply With Quote
  #5  
Old 09-02-2008, 07:17 PM
MoT3rror MoT3rror is offline
 
Join Date: Mar 2007
Posts: 423
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Like I said you are getting a database error. Use mysql_error(); to get the error text.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:41 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06084 seconds
  • Memory Usage 2,198KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete