Ahaa, i found the bug. Thats my code, but where to place include "menu_right.php"; to work fine?I dont knowo wher is finish the container...
<?php
class headers {
function startheaders() {
global $ir, $set;
global $_CONFIG;
define("MONO_ON", 1);
$db=new database;
$db->configure($_CONFIG['hostname'],
$_CONFIG['username'],
$_CONFIG['password'],
$_CONFIG['database'],
$_CONFIG['persistent']);
$db->connect();
$c=$db->connection_id;
$set=array();
$settq=$db->query("SELECT * FROM settings");
while($r=$db->fetch_row($settq))
{
$set[$r['conf_name']]=$r['conf_value'];
}
$q=$db->query("SELECT userid FROM users");
$membs=$db->num_rows($q);
$q=$db->query("SELECT userid FROM users WHERE bankmoney>-1");
$banks=$db->num_rows($q);
$q=$db->query("SELECT userid FROM users WHERE gender='Male'");
$male=$db->num_rows($q);
$q=$db->query("SELECT userid FROM users WHERE gender='Female'");
$fem=$db->num_rows($q);
$money=money_formatter($ir['money']);
$crystals=money_formatter($ir['crystals'],'');
$cn=0;
// Users Online , Counts Users Online In Last 15 minutes
$q=$db->query("SELECT * FROM users WHERE laston>unix_timestamp()-15*60 ORDER BY laston DESC");
$online=$db->num_rows($q);
$ec=$ir['new_events'];
$mc=$ir['new_mail'];
$ids_checkpost=urldecode($_SERVER['QUERY_STRING']);
if(eregi("[\'|'/'\''<'>'*'~'`']",$ids_checkpost) || strstr($ids_checkpost,'union') || strstr($ids_checkpost,'java') || strstr($ids_checkpost,'script') || strstr($ids_checkpost,'substring(') || strstr($ids_checkpost,'ord()')){
$passed=0;
echo "<center> <font color=red> Hack attempt <br/>!!! WARNING !!! <br/>
Malicious Code Detected! The staff has been notified.</font></center>";
event_add(1," <a href='viewuser.php?u={$ir['userid']}'> <font color=red> ".$ir['username']."</font> </a> <b> Tried to use [".$_SERVER['SCRIPT_NAME']."{$ids_checkpost}].. ",$c);
$h->endpage();
exit;
}
echo <<<EOF
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<title>{$set['game_name']} - Massive Multiplayer Online Role Playing Game </title>
<meta name="keywords" content="RPG, Online Games, Online Mafia Game" />
<meta name="description" content=" {$set['game_name']} - Online Mafia Game " />
<meta name="author" content="Mafia Game Scripts " />
<meta name="copyright" content="Copyright {$_SERVER['HTTP_HOST']} " />
<link rel="SHORTCUT ICON" href="favicon.ico" />
<script src="js/jquery-1.js" type="text/javascript"></script>
<link rel="stylesheet" href="css/wcg.css" type="text/css" />
<script type="text/javascript" src="js/header.js"></script>
<style type="text/css">
.boston a{
background:url(images/boston.jpg) no-repeat;
}
.boston a:hover{
background:url(images/boston_hover.jpg) no-repeat;
}
</style>
<!--<script type="text/javascript">
$(document).ready(function(){
$.get("userstatajax.php",function(res){
if(res)
{
var resarray = res.split('||||||');
$('.profile_mid').html(resarray[0]);
$('#points_money').html(resarray[1]);
}
});
});
</script>-->
<Script language="JavaScript">
<!--
window.IMAGEPATH = "http://thecrims.cachefly.net/images/";
document.addEventListener("DOMNodeInserted",bdcbccabedbe, true);
document.addEventListener("DOMAttrModified",bfdedceaea, true);
document.addEventListener("DOMNodeRemoved",fccbafca, true);
function cbcaadb(name) {
var tags = new Array('SPAN','TR','TD');
for(x in tags) {
if(name == tags[x])
return false;
}
return true;
}
function ddaaefaa(evt){
if (typeof(window.event) != 'undefined')
return window.event.srcElement;
else
return evt.target;
}
function ccfcfcfdf(tagName) {
}
function bdcbccabedbe(event) {
if(typeof(event.target.tagName) != 'undefined' && cbcaadb(event.target.tagName) == false) {
srcElement = ddaaefaa(event);
if(typeof(srcElement) != 'undefined')
$(srcElement).remove();
ccfcfcfdf(event.target.tagName);
}
}
function bfdedceaea(event) {
if(event.target.tagName == 'OPTION') {
ccfcfcfdf(event.target.tagName);
}
}
function fccbafca(event) {
var srcElement = ddaaefaa(event);
if(srcElement && srcElement.attributes && srcElement.attributes.length) {
$(srcElement).remove();
}
if(typeof(event.target.id) != 'undefined' && typeof(event.target.tagName) != 'undefined' && (event.target.id == 'topbox' || event.target.tagName == 'IFRAME' || event.target.id == 'banner_bottom')) {
ccfcfcfdf(event.target.tagName);
}
}
function confirmChoice() {
var value = confirm("Esti sigur?");
if (value == true) {
wait();
return true;
} else {
return false;
}
}
function checkBox(value)
{
if(value == '-')
{
alert("Alege din lista");
return false;
}
else
{
wait();
return true;
}
}
// -->
</script>
</head>
<!-- // Flas Header Part Stars -->
<div class="flashpartig">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=7,0,19,0" width="950" height="235" title="TheGangsters.ro">
<param name="movie" value="images/flash/header.swf" />
<param name="quality" value="high" />
<param name="wmode" value="Transparent" />
<embed src="images/flash/header.swf" quality="high" wmode="transparent" pluginspage="http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash" width="950" height="235"></embed>
</object>
</div>
<!-- //Flash Header Part End -->
<!-- Container Part Starts -->
<div id="centercontainer">
<div id="centermaincontainer">
<!-- Container Part Ends -->
<!-- Center Part Starts -->
<div class="icenterpart"><div class="icolumn1">
EOF;
}
function userdata($ir,$lv,$fm,$cm,$dosessh=1)
{
global $db,$c,$userid, $set;
$IP = $_SERVER['REMOTE_ADDR'];
$IP=addslashes($IP);
$IP=mysql_real_escape_string($IP);
$IP=strip_tags($IP);
$db->query("UPDATE users SET laston=unix_timestamp(),lastip='$IP' WHERE userid=$userid");
$_GET['ID'] = abs(@intval($_GET['ID']));
$_GET['reply'] = abs(@intval($_GET['reply']));
if(!$ir['email'])
{
global $domain;
die ("<body>Your account may be broken. Please mail help@{$domain} stating your username and player ID.");
}
if($dosessh && ($_SESSION['attacking'] || $ir['attacking']))
{
print "<CENTER><P><b><font color=red>You lost all your EXP for running from the fight.</font></b></P></CENTER> <br/><br/>";
$db->query("UPDATE users SET exp=0,attacking=0 WHERE userid=$userid");
$_SESSION['attacking']=0;
}
include "rank.php";
$enperc=(int) ($ir['energy']/$ir['maxenergy']*100);
$wiperc=(int) ($ir['will']/$ir['maxwill']*100);
$experc=(int) ( $ir['exp']/$ir['exp_needed']*100);
$brperc=(int) ($ir['brave']/$ir['maxbrave']*100);
$hpperc=(int) ($ir['hp']/$ir['maxhp']*100);
$enopp=100-$enperc;
$wiopp=100-$wiperc;
$exopp=100-$experc;
$bropp=100-$brperc;
$hpopp=100-$hpperc;
$d="";
$u=$ir['username'];
if($ir['donatordays']) { $u = "<font color=green>{$ir['username']}</font>";$d="<img src='donator.gif' alt='Donator: {$ir['donatordays']} Days Left' title='Donator: {$ir['donatordays']} Days Left' />"; }
$gn="";
global $staffpage;
$bgcolor = 'FFFFFF';
if($ir['fedjail'])
{
$q=$db->query("SELECT * FROM fedjail WHERE fed_userid=$userid");
$r=$db->fetch_row($q);
die(" <br /><br /><br /><br /><br /> <CENTER><P> <b><font color=red size=+1>You have been put in the {$set['game_name']} Federal Jail for {$r['fed_days']} day(s).<br /> <br />
Reason: {$r['fed_reason']}</font></b> </P></CENTER> </body></html>");
}
if(file_exists('ipbans/'.$IP))
{
die("<br /><br /><br /><br /><br /><CENTER><P><b><font color=red size=+1>Your IP has been banned from {$set['game_name']}, there is no way around this.</font></b></P></CENTER></body></html>");
}
include "menu_right.php";
}
function menu_left()
{
include "menu_left.php";
global $ir,$c;
$bgcolor = '';
print '</td><td width="2" class="linegrad" bgcolor="#'.$bgcolor.'"> </td><td width="80%" bgcolor="#'.$bgcolor.'" valign="top"><center>';
if($ir['hospital'])
{
print "<div class='generalinfo_simple'><br/><font color='yellow'><center<b><div class='statusbox_ok'>Esti internat in spital pentru {$ir['hospital']} de minute. Data viitoare ai grija!</div></b><center></font><br/></div>";
}
if($ir['jail'])
{
print "<div class='generalinfo_simple'><br/><font color='red'><center<b><div class='statusbox_ok'>Esti in inchisoare timp de {$ir['jail']} minute. Data viitoare ai grija!</div></b><center></font><br/></div>";
}
if($ir['bguard'] >0)
{
print "<font color='green'><b>NOTE:</b></font> Your Bodyguard is protecting you for {$ir['bguard']} more minutes.<br/><br/>";
}
}
function smenuarea()
{
include "smenu.php";
global $ir,$c;
$bgcolor = '';
print '</td><td width="2" class="linegrad" bgcolor="#'.$bgcolor.'"> </td><td width="80%" bgcolor="#'.$bgcolor.'" valign="top"><center>';
}
function endpage()
{
global $db;
include "footer.php";
}
}
?>