MOON
Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 PHP/5.4.10
System: Linux vps.presagepowered.net 2.6.18-398.el5 #1 SMP Tue Sep 16 20:51:48 EDT 2014 i686
User: mckernan (512)
PHP: 5.4.10
Disabled: NONE
Upload Files
File: /home/mckernan/public_html/iJournal/includes/tracker/saventry.php
<?php

// add / update tracker entry item

    // init database name
	$database = DB_PREFIX;	
    
    // process request
	if ($sid != '')
	{
		// sid check
		require "includes/session/sidck.php";
        
        // init return value
		$rv = '<root>' . PHP_EOL;
	
	
		// fetch database name / open db
		$dbname = '';
		if ( isset($_POST['db']) ) $dbname = $_POST['db'];
		if ( isset($_GET['db']) ) $dbname = $_GET['db'];
		
		if ($dbname == '') die();
		
		$database .= $dbname;
        
        require "includes/db.php";
        
        
        // fetch / validate params
		$entryid = getvar($db, 'eid', 'int');
        $itemid = getvar($db, 'tid', 'int');
        $perid = getvar($db, 'pid', 'int');
        $amt = getvar($db, 'amt', 'float');
        
        
        if ($entryid < 1)
		{
            $query = "INSERT INTO tracking (trkg_tracker, trkg_per, trkg_amt) VALUES (" . $itemid . ", " . $perid . ", " . $amt . ")";
        }
        else
        {
            $query = "UPDATE tracking SET trkg_amt = " . $amt . " WHERE trkg_id = " . $entryid;
        }
          
          
        if ($result = $db->query($query))
        {
            if ($db->affected_rows == 1)
            {
            	$rv .= "<success>true</success>" . PHP_EOL;
                
            }
            else
            {
                $rv .= "<success></success>" . PHP_EOL;
            }  
        }
        else
        {
            $rv .= "<success></success>" . PHP_EOL;
        }
        
        
        // finish output
        $rv .= '</root>' . PHP_EOL;
        
        
        // return data
        echo $rv;
        
        die;
	}
	else
	{
		header('Server: ');
		header('X-Powered-By: ');
		header("HTTP/1.0 404 Not Found");
	}

?>