HEX
Server: Apache/2.4.18 (Ubuntu)
System: Linux ubuntu 7.0.5-x86_64-linode173 #1 SMP PREEMPT_DYNAMIC Fri May 8 10:12:05 EDT 2026 x86_64
User: root (0)
PHP: 7.2.28-1+ubuntu16.04.1+deb.sury.org+1
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: //proc/thread-self/root/opt/code/static/api/login.php
<?php 
$dir = dirname(__FILE__);
include_once($dir.'/util.php');
include_once($dir.'/db.php');
session_start();

$db = &$_SERVER['DB'];
$res = $db->query('SELECT id FROM account WHERE email = "'.$db->escape($_REQUEST['username']).'" AND secret = "'.$db->escape($_REQUEST['password']).'"');
if(!$db->count($res))
{
	// ask authorization again
  header('HTTP/1.0 401 Unauthorized', true, 401);
  echo 'Wrong username or password';
	die;
}
else $_SESSION['uid'] = $db->get_res($res);

if($_SESSION['uid'] == 1) header('X-ADMIN: 1');
echo '{"login":true}';

?>