EVE-KILL /
zKillboard
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | /* zKillboard |
||
| 3 | * Copyright (C) 2012-2015 EVE-KILL Team and EVSCO. |
||
| 4 | * |
||
| 5 | * This program is free software: you can redistribute it and/or modify |
||
| 6 | * it under the terms of the GNU Affero General Public License as published by |
||
| 7 | * the Free Software Foundation, either version 3 of the License, or |
||
| 8 | * (at your option) any later version. |
||
| 9 | * |
||
| 10 | * This program is distributed in the hope that it will be useful, |
||
| 11 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
| 12 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
| 13 | * GNU Affero General Public License for more details. |
||
| 14 | * |
||
| 15 | * You should have received a copy of the GNU Affero General Public License |
||
| 16 | * along with this program. If not, see <http://www.gnu.org/licenses/>. |
||
| 17 | */ |
||
| 18 | |||
| 19 | // Find the allianceID |
||
| 20 | if(!is_numeric($alliance)) |
||
| 21 | $allianceID = (int) Db::queryField("SELECT allianceID FROM zz_alliances WHERE name = :name", "allianceID", array(":name" => $alliance), 3600);
|
||
| 22 | else // Verify it exists |
||
| 23 | $allianceID = (int) Db::queryField("SELECT allianceID FROM zz_alliances WHERE allianceID = :allianceID", "allianceID", array(":allianceID" => (int) $alliance), 3600);
|
||
| 24 | |||
| 25 | // If the allianceID we get from above is zero, don't even bother anymore..... |
||
| 26 | if($allianceID == 0) |
||
| 27 | $app->redirect("/");
|
||
| 28 | elseif(!is_numeric($alliance)) // if alliance isn't numeric, we redirect TO the allianceID! |
||
| 29 | $app->redirect("/alliance/{$allianceID}/");
|
||
| 30 | |||
| 31 | // Now we figure out all the parameters |
||
| 32 | $parameters = Util::convertUriToParameters(); |
||
| 33 | |||
| 34 | // Unset the alliance => id, and make it allianceID => id |
||
| 35 | unset($parameters["alliance"]); |
||
| 36 | $parameters["allianceID"] = $allianceID; |
||
| 37 | $parameters["index"] = "allianceID_dttm"; |
||
| 38 | |||
| 39 | // Make sure that the pageType is correct.. |
||
| 40 | $subPageTypes = array("page", "month", "year", "shipTypeID");
|
||
| 41 | if(in_array($pageType, $subPageTypes)) |
||
| 42 | $pageType = "overview"; |
||
| 43 | |||
| 44 | // Some defaults |
||
| 45 | @$page = max(1, $parameters["page"]); |
||
|
0 ignored issues
–
show
|
|||
| 46 | $limit = 50; |
||
| 47 | $parameters["limit"] = $limit; |
||
| 48 | $parameters["page"] = $page; |
||
| 49 | |||
| 50 | // and now we fetch the info! |
||
| 51 | $detail = Info::getAlliDetails($allianceID, $parameters); |
||
| 52 | |||
| 53 | // Define the page information and scope etc. |
||
| 54 | $pageName = isset($detail["allianceName"]) ? $detail["allianceName"] : "???"; |
||
| 55 | $columnName = "allianceID"; |
||
| 56 | $mixedKills = $pageType == "overview" && UserConfig::get("mixKillsWithLosses", true);
|
||
| 57 | |||
| 58 | // Load kills for the various pages. |
||
| 59 | $mixed = $pageType == "overview" ? Kills::getKills($parameters) : array(); |
||
| 60 | $kills = $pageType == "kills" ? Kills::getKills($parameters) : array(); |
||
| 61 | $losses = $pageType == "losses" ? Kills::getKills($parameters) : array(); |
||
| 62 | |||
| 63 | // Solo parameters |
||
| 64 | //$soloParams = $parameters; |
||
| 65 | //if (!isset($parameters["kills"]) || !isset($parameters["losses"])) {
|
||
| 66 | // $soloParams["mixed"] = true; |
||
| 67 | //} |
||
| 68 | |||
| 69 | // Solo kills |
||
| 70 | //$soloKills = Kills::getKills($soloParams); |
||
| 71 | //$solo = Kills::mergeKillArrays($soloKills, array(), $limit, $columnName, $allianceID); |
||
| 72 | |||
| 73 | |||
| 74 | $topLists = array(); |
||
| 75 | $topKills = array(); |
||
| 76 | if($pageType == "groupID") |
||
| 77 | $app->redirect("/");
|
||
| 78 | |||
| 79 | if ($pageType == "top" || $pageType == "topalltime") {
|
||
| 80 | $topParameters = $parameters; // array("limit" => 10, "kills" => true, "$columnName" => $allianceID);
|
||
| 81 | $topParameters["limit"] = 10; |
||
| 82 | |||
| 83 | if ($pageType != "topalltime") {
|
||
| 84 | if (!isset($topParameters["year"])) {
|
||
| 85 | $topParameters["year"] = date("Y");
|
||
| 86 | } |
||
| 87 | |||
| 88 | if (!isset($topParameters["month"])) {
|
||
| 89 | $topParameters["month"] = date("m");
|
||
| 90 | } |
||
| 91 | |||
| 92 | } |
||
| 93 | if (!array_key_exists("kills", $topParameters) && !array_key_exists("losses", $topParameters)) {
|
||
| 94 | $topParameters["kills"] = true; |
||
| 95 | } |
||
| 96 | |||
| 97 | $topLists[] = array("type" => "character", "data" => Stats::getTopPilots($topParameters, true));
|
||
| 98 | $topLists[] = array("type" => "corporation", "data" => Stats::getTopCorps($topParameters, true));
|
||
| 99 | $topLists[] = array("type" => "alliance", "data" => Stats::getTopAllis($topParameters, true));
|
||
| 100 | $topLists[] = array("type" => "ship", "data" => Stats::getTopShips($topParameters, true));
|
||
| 101 | $topLists[] = array("type" => "system", "data" => Stats::getTopSystems($topParameters, true));
|
||
| 102 | $topLists[] = array("type" => "weapon", "data" => Stats::getTopWeapons($topParameters, true));
|
||
| 103 | } |
||
| 104 | else |
||
| 105 | {
|
||
| 106 | $p = $parameters; |
||
| 107 | $numDays = 7; |
||
| 108 | $p["limit"] = 10; |
||
| 109 | $p["pastSeconds"] = $numDays * 86400; |
||
| 110 | $p["kills"] = $pageType != "losses"; |
||
| 111 | |||
| 112 | $topLists[] = Info::doMakeCommon("Top Characters", "characterID", Stats::getTopPilots($p));
|
||
| 113 | $topLists[] = Info::doMakeCommon("Top Corporations", "corporationID", Stats::getTopCorps($p));
|
||
| 114 | $topLists[] = Info::doMakeCommon("Top Ships", "shipTypeID", Stats::getTopShips($p));
|
||
| 115 | $topLists[] = Info::doMakeCommon("Top Systems", "solarSystemID", Stats::getTopSystems($p));
|
||
| 116 | |||
| 117 | $p["limit"] = 5; |
||
| 118 | $topKills = Stats::getTopIsk($p); |
||
| 119 | } |
||
| 120 | |||
| 121 | // Load the list of corporations with API information |
||
| 122 | $corpList = array(); |
||
| 123 | if ($pageType == "api") |
||
| 124 | $corpList = Info::getCorps($allianceID); |
||
| 125 | |||
| 126 | // Load the corporation stats! |
||
| 127 | $corpStats = array(); |
||
| 128 | if ($pageType == "corpstats") |
||
| 129 | $corpStats = Info::getCorpStats($allianceID, $parameters); |
||
| 130 | |||
| 131 | // Fix the history data! |
||
| 132 | $detail["history"] = $pageType == "stats" ? Summary::getMonthlyHistory($columnName, $allianceID) : array(); |
||
| 133 | |||
| 134 | // Stats |
||
| 135 | $cnt = 0; |
||
| 136 | $cnid = 0; |
||
| 137 | $stats = array(); |
||
| 138 | $totalcount = ceil(count($detail["stats"]) / 4); |
||
| 139 | foreach ($detail["stats"] as $q) {
|
||
| 140 | if ($cnt == $totalcount) {
|
||
| 141 | $cnid++; |
||
| 142 | $cnt = 0; |
||
| 143 | } |
||
| 144 | $stats[$cnid][] = $q; |
||
| 145 | $cnt++; |
||
| 146 | } |
||
| 147 | |||
| 148 | // Mixed kills yo! |
||
| 149 | if ($mixedKills) |
||
| 150 | $kills = Kills::mergeKillArrays($mixed, array(), $limit, $columnName, $allianceID); |
||
| 151 | |||
| 152 | // Find the next and previous allianceID |
||
| 153 | $prevID = Db::queryField("select allianceID from zz_alliances where allianceID < :id order by allianceID desc limit 1", "allianceID", array(":id" => $allianceID), 300);
|
||
| 154 | $nextID = Db::queryField("select allianceID from zz_alliances where allianceID > :id order by allianceID asc limit 1", "allianceID", array(":id" => $allianceID), 300);
|
||
| 155 | |||
| 156 | // Wars |
||
| 157 | $warID = (int) $allianceID; |
||
| 158 | $extra = array(); |
||
| 159 | $extra["hasWars"] = Db::queryField("select count(distinct warID) count from zz_wars where aggressor = $warID or defender = $warID", "count");
|
||
| 160 | $extra["wars"] = array(); |
||
| 161 | if ($pageType == "wars" && $extra["hasWars"]) {
|
||
| 162 | $extra["wars"][] = War::getNamedWars("Active Wars - Aggressor", "select * from zz_wars where aggressor = $warID and timeFinished is null order by timeStarted desc");
|
||
| 163 | $extra["wars"][] = War::getNamedWars("Active Wars - Defending", "select * from zz_wars where defender = $warID and timeFinished is null order by timeStarted desc");
|
||
| 164 | $extra["wars"][] = War::getNamedWars("Closed Wars - Aggressor", "select * from zz_wars where aggressor = $warID and timeFinished is not null order by timeFinished desc");
|
||
| 165 | $extra["wars"][] = War::getNamedWars("Closed Wars - Defending", "select * from zz_wars where defender = $warID and timeFinished is not null order by timeFinished desc");
|
||
| 166 | } |
||
| 167 | |||
| 168 | /*$extra["supers"] = array(); |
||
| 169 | if ($pageType == "supers") |
||
| 170 | {
|
||
| 171 | $minKillID = Db::queryField("select min(killID) killID from zz_participants where dttm >= date_sub(now(), interval 90 day) and dttm < date_sub(now(), interval 89 day)", "killID", array(), 900);
|
||
| 172 | $months = 3; |
||
| 173 | $data = array(); |
||
| 174 | $data["titans"]["data"] = Db::query("SELECT distinct characterID, count(distinct killID) kills, shipTypeID FROM zz_participants WHERE killID >= $minKillID AND isVictim = 0 AND groupID = 30 AND allianceID = :id GROUP BY characterID ORDER BY 2 DESC", array(":id" => $allianceID), 900);
|
||
| 175 | $data["titans"]["title"] = "Titans"; |
||
| 176 | |||
| 177 | $data["moms"]["data"] = Db::query("SELECT distinct characterID, count(distinct killID) kills, shipTypeID FROM zz_participants WHERE killID >= $minKillID AND isVictim = 0 AND groupID = 659 AND allianceID = :id GROUP BY characterID ORDER BY 2 DESC", array(":id" => $allianceID), 900);
|
||
| 178 | $data["moms"]["title"] = "Supercarriers"; |
||
| 179 | |||
| 180 | Info::addInfo($data); |
||
| 181 | $extra["supers"] = $data; |
||
| 182 | }*/ |
||
| 183 | |||
| 184 | if($pageType == "members") |
||
| 185 | {
|
||
| 186 | $memberLimit = 100; |
||
| 187 | $offset = ($page - 1) * $memberLimit; |
||
| 188 | $extra["memberList"] = Db::query("SELECT * FROM zz_characters WHERE allianceID = :allianceID ORDER BY name LIMIT $offset, $memberLimit", array(":allianceID" => $allianceID));
|
||
| 189 | $extra["memberCount"] = Db::queryField("SELECT count(*) AS count FROM zz_characters WHERE allianceID = :allianceID", "count", array(":allianceID" => $allianceID));
|
||
| 190 | foreach($extra["memberList"] as $key => $data) |
||
| 191 | {
|
||
| 192 | $characterID = $data["characterID"]; |
||
| 193 | $corporationID = $data["corporationID"]; |
||
| 194 | $lastSeenSystemID = Db::queryField("SELECT solarSystemID FROM zz_participants WHERE characterID = :charID ORDER BY dttm DESC LIMIT 1", "solarSystemID", array(":charID" => $characterID));
|
||
| 195 | $extra["memberList"][$key]["lastSeenSystem"] = $lastSeenSystemID > 0 ? Info::getSystemName($lastSeenSystemID) : "Not Seen"; |
||
| 196 | $extra["memberList"][$key]["lastSeenRegion"] = $lastSeenSystemID > 0 ? Info::getRegionName(Info::getRegionIDFromSystemID($lastSeenSystemID)) : "Not Seen"; |
||
| 197 | $extra["memberList"][$key]["lastSeenDate"] = Db::queryField("SELECT dttm FROM zz_participants WHERE characterID = :charID ORDER BY dttm DESC LIMIT 1", "dttm", array(":charID" => $characterID));
|
||
| 198 | $extra["memberList"][$key]["lastSeenShip"] = Info::getShipName(Db::queryField("SELECT shipTypeID FROM zz_participants WHERE characterID = :charID AND shipTypeID != 0 ORDER BY dttm DESC LIMIT 1", "shipTypeID", array(":charID" => $characterID)));
|
||
| 199 | $extra["memberList"][$key]["lifeTimeKills"] = Db::queryField("SELECT SUM(destroyed) AS kills FROM zz_stats WHERE typeID = :charID", "kills", array(":charID" => $characterID), 3600);
|
||
| 200 | $extra["memberList"][$key]["lifeTimeLosses"] = Db::queryField("SELECT SUM(lost) AS losses FROM zz_stats WHERE typeID = :charID", "losses", array(":charID" => $characterID), 3600);
|
||
| 201 | } |
||
| 202 | } |
||
| 203 | |||
| 204 | $renderParams = array( |
||
| 205 | "pageName" => $pageName, |
||
| 206 | "kills" => $kills, |
||
| 207 | "losses" => $losses, |
||
| 208 | "detail" => $detail, |
||
| 209 | "page" => $page, |
||
| 210 | "topKills" => $topKills, |
||
| 211 | "mixed" => $mixedKills, |
||
| 212 | "key" => "alliance", |
||
| 213 | "id" => $allianceID, |
||
| 214 | "pageType" => $pageType, |
||
| 215 | // "solo" => $solo, |
||
| 216 | "topLists" => $topLists, |
||
| 217 | "corps" => $corpList, |
||
| 218 | "corpStats" => $corpStats, |
||
| 219 | "summaryTable" => $stats, |
||
| 220 | "pager" => (sizeof($kills) + sizeof($losses) >= $limit), |
||
| 221 | "datepicker" => true, |
||
| 222 | "prevID" => $prevID, |
||
| 223 | "nextID" => $nextID, |
||
| 224 | "pager" => true, |
||
| 225 | "datepicker" => false, |
||
| 226 | "extra" => $extra |
||
| 227 | ); |
||
| 228 | |||
| 229 | $app->etag(md5(serialize($renderParams))); |
||
| 230 | $app->expires("+5 minutes");
|
||
| 231 | $app->render("overview.html", $renderParams);
|
||
| 232 |
If you suppress an error, we recommend checking for the error condition explicitly: