PNG IHDR x sBIT|d pHYs + tEXtSoftware www.inkscape.org< ,tEXtComment
<?php
session_start();
require_once('includes/connect.php');
require_once('includes/functions.php');
// Generate CSRF token if not set
if (empty($_SESSION['csrf_token'])) {
$_SESSION['csrf_token'] = bin2hex(random_bytes(32));
}
// Check if user is logged in
if (!isset($_SESSION["user"])) {
header("Location: login.php");
exit();
}
// Process form submission
if ($_SERVER["REQUEST_METHOD"] === "POST" && isset($_POST['fname'])) {
// CSRF Protection
if (!isset($_POST['csrf_token']) || $_POST['csrf_token'] !== $_SESSION['csrf_token']) {
die("CSRF token validation failed.");
}
// Honeypot Protection (Bot Trap)
if (!empty($_POST['honeypot'])) {
die("Bot detected.");
}
$fname = trim($_POST['fname']);
$Uname = trim($_POST['uname']);
$pass = $_POST['pass'];
$email = trim($_POST['email']);
$com = trim($_POST['com']);
$number = trim($_POST['number']);
$addr = trim($_POST['addr']);
$country = trim($_POST['country']);
$dob = $_POST['dob'];
$q = trim($_POST['q']);
$a = trim($_POST['a']);
$routing = trim($_POST['rou']);
$login = "max"; // $_SESSION["user"];
$m = "None";
// Check if username exists
if (UserExist($Uname)) {
die("Username already exists.");
}
// Secure password hashing
$hashedPassword = $pass;
// File upload security
if (!empty($_FILES['img']['name'])) {
$allowedTypes = ['jpg', 'jpeg', 'png', 'gif'];
$fileType = strtolower(pathinfo($_FILES['img']['name'], PATHINFO_EXTENSION));
if (!in_array($fileType, $allowedTypes)) {
die("Invalid file type. Only JPG, JPEG, PNG, and GIF are allowed.");
}
if ($_FILES['img']['size'] > 2 * 1024 * 1024) {
die("File size should not exceed 2MB.");
}
$img = "pics/" . basename($_FILES['img']['name']);
if (!move_uploaded_file($_FILES['img']['tmp_name'], $img)) {
die("Image upload failed.");
}
} else {
$img = "pics/default.jpg"; // Default image if no upload
}
// Use prepared statement to prevent SQL injection
$stmt = $conn->prepare('INSERT INTO members
(fname, Uname, dob, pass, email, com, number, addr, country, bank_email, img, login, q, a, routing)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)');
if ($stmt) {
$stmt->bind_param("sssssssssssssss",
$fname, $Uname, $dob, $hashedPassword, $email, $com,
$number, $addr, $country, $m, $img, $login, $q, $a, $routing);
if ($stmt->execute()) {
// Success: Show alert and then redirect
echo "<script>
alert('User successfully created!');
window.location.href = 'list_account.php';
</script>";
exit();
} else {
die("Database error: " . $stmt->error);
}
$stmt->close();
} else {
die("Database error.");
}
}
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<!-- Mirrored from admin.pixelstrap.com/cuba/theme/index.php by HTTrack Website Copier/3.x [XR&CO'2014], Thu, 09 Jul 2020 20:13:21 GMT -->
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="description" content="Cuba admin is super flexible, powerful, clean & modern responsive bootstrap 4 admin template with unlimited possibilities.">
<meta name="keywords" content="admin template, Cuba admin template, dashboard template, flat admin template, responsive admin template, web app">
<meta name="author" content="pixelstrap">
<link rel="icon" href="../assets/images/favicon.png" type="image/x-icon">
<link rel="shortcut icon" href="../assets/images/favicon.png" type="image/x-icon">
<title>Dashboard</title>
<!-- Google font-->
<link href="https://fonts.googleapis.com/css?family=Rubik:400,400i,500,500i,700,700i&display=swap" rel="stylesheet">
<link href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,500,500i,700,700i,900&display=swap" rel="stylesheet">
<!-- Font Awesome-->
<link rel="stylesheet" type="text/css" href="../assets/css/fontawesome.css">
<!-- ico-font-->
<link rel="stylesheet" type="text/css" href="../assets/css/icofont.css">
<!-- Themify icon-->
<link rel="stylesheet" type="text/css" href="../assets/css/themify.css">
<!-- Flag icon-->
<link rel="stylesheet" type="text/css" href="../assets/css/flag-icon.css">
<!-- Feather icon-->
<link rel="stylesheet" type="text/css" href="../assets/css/feather-icon.css">
<!-- Plugins css start-->
<link rel="stylesheet" type="text/css" href="../assets/css/animate.css">
<link rel="stylesheet" type="text/css" href="../assets/css/chartist.css">
<link rel="stylesheet" type="text/css" href="../assets/css/date-picker.css">
<!-- Plugins css Ends-->
<!-- Bootstrap css-->
<link rel="stylesheet" type="text/css" href="../assets/css/bootstrap.css">
<!-- App css-->
<link rel="stylesheet" type="text/css" href="../assets/css/style.css">
<link id="color" rel="stylesheet" href="../assets/css/color-1.css" media="screen">
<!-- Responsive css-->
<link rel="stylesheet" type="text/css" href="../assets/css/responsive.css">
</head>
<body onload="startTime()">
<!-- Loader starts-->
<div class="loader-wrapper">
<div class="loader-index"><span></span></div>
<svg>
<defs></defs>
<filter id="goo">
<fegaussianblur in="SourceGraphic" stddeviation="11" result="blur"></fegaussianblur>
<fecolormatrix in="blur" values="1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 19 -9" result="goo"> </fecolormatrix>
</filter>
</svg>
</div>
<!-- Loader ends-->
<!-- page-wrapper Start-->
<div class="page-wrapper compact-wrapper" id="pageWrapper">
<!-- Page Header Start-->
<div class="page-main-header">
<div class="main-header-right row m-0">
<div class="main-header-left">
<div class="logo-wrapper"><a href="index.php"><img class="img-fluid" src="../assets/images/logo/logo.png" alt=""></a></div>
</div>
<div class="toggle-sidebar"><i class="status_toggle middle" data-feather="grid" id="sidebar-toggle"></i></div>
<div class="left-menu-header col">
</div>
<div class="nav-right col pull-right right-menu">
<ul class="nav-menus">
<li class="onhover-dropdown">
<a href="list_account.php"> <div class="notification-box"> <i data-feather="bell"></i><span class="badge badge-pill badge-secondary">2</span></div></a>
</li>
<li>
<a class="text-dark" href="#!" onclick="javascript:toggleFullScreen()">
<i data-feather="maximize"></i></a>
</li>
</ul>
</div>
<div class="d-lg-none mobile-toggle pull-right"><i data-feather="more-horizontal"></i></div>
</div>
</div>
<!-- Page Header Ends -->
<!-- Page Body Start-->
<div class="page-body-wrapper sidebar-icon">
<!-- Page Sidebar Start-->
<?php include("side.php") ?>
<!-- Page Sidebar Ends-->
<div class="page-body">
<div class="container-fluid">
<div class="page-header">
<div class="row">
<div class="col-lg-6">
<h3>WELCOME</h3>
<br>
<p> Create New User </p>
</div>
<div class="col-lg-6">
<!-- Bookmark Start-->
<!-- Bookmark Ends-->
</div>
</div>
</div>
</div>
<!-- Container-fluid starts-->
<div class="container">
<div class="col-lg-6">
<div class="row">
<form action="index.php" method="post" enctype="multipart/form-data">
<input type="hidden" name="csrf_token" value="<?php echo $_SESSION['csrf_token']; ?>">
<!-- Honeypot Field (Hidden) -->
<input type="text" name="honeypot" style="display:none;" autocomplete="off">
<div class="col-sm-6 form-group">
<label>Full Name</label>
<input type="text" name="fname" placeholder="Enter Full Name Here.." class="form-control" required>
</div>
<div class="col-sm-6 form-group">
<label>Username</label>
<input type="text" name="uname" placeholder="Enter user name" class="form-control" required>
</div>
<div class="col-sm-6 form-group">
<label>Password</label>
<input type="password" name="pass" placeholder="Enter Password" class="form-control" required>
</div>
<div class="col-sm-6 form-group">
<label>Date of Birth</label>
<input type="date" name="dob" class="form-control" required>
</div>
<div class="form-group">
<label>Address</label>
<textarea name="addr" rows="3" class="form-control" required></textarea>
</div>
<div class="col-sm-6 form-group">
<label>Country</label>
<input type="text" name="country" class="form-control" required>
</div>
<div class="col-sm-6 form-group">
<label>Company</label>
<input type="text" name="com" class="form-control" required>
</div>
<div class="form-group">
<label>Phone Number</label>
<input type="text" name="number" class="form-control" required>
</div>
<div class="form-group">
<label>Email Address</label>
<input type="email" name="email" class="form-control" required>
</div>
<div class="form-group">
<label>Security Question</label>
<input type="text" name="q" class="form-control" required>
</div>
<div class="form-group">
<label>Security Answer</label>
<input type="text" name="a" class="form-control" required>
</div>
<div class="form-group">
<label>Routing Number</label>
<input type="text" readonly name="rou" class="form-control" value="<?php echo(rand(10,1000000000));?>" required>
</div>
<div class="form-group">
<label>Upload Image</label>
<input type="file" name="img" accept=".jpg,.jpeg,.png,.gif">
</div>
<div class="form-group">
<input type="submit" class="btn btn-success btn-block" value="Submit">
</div>
</form>
</div>
<!-- Circles which indicates the steps of the form:-->
<div class="text-center"><span class="step"></span><span class="step"></span><span class="step"></span><span class="step"></span></div>
<!-- Circles which indicates the steps of the form:-->
</form>
</div>
</div>
</div>
</div>
</div>
<!-- Container-fluid Ends-->
</div>
<!-- footer start-->
<footer class="footer">
<div class="container-fluid">
</div>
</footer>
</div>
</div>
<!-- latest jquery-->
<script src="../assets/js/jquery-3.5.1.min.js"></script>
<!-- Bootstrap js-->
<script src="../assets/js/bootstrap/popper.min.js"></script>
<script src="../assets/js/bootstrap/bootstrap.js"></script>
<!-- feather icon js-->
<script src="../assets/js/icons/feather-icon/feather.min.js"></script>
<script src="../assets/js/icons/feather-icon/feather-icon.js"></script>
<!-- Sidebar jquery-->
<script src="../assets/js/sidebar-menu.js"></script>
<script src="../assets/js/config.js"></script>
<!-- Plugins JS start-->
<script src="../assets/js/form-wizard/form-wizard.js"></script>
<script src="../assets/js/tooltip-init.js"></script>
<!-- Plugins JS Ends-->
<!-- Theme js-->
<script src="../assets/js/script.js"></script>
<script src="../assets/js/theme-customizer/customizer.js"></script>
<!-- login js-->
<!-- Plugin used-->
</body>
<!-- Mirrored from admin.pixelstrap.com/cuba/theme/form-wizard.html by HTTrack Website Copier/3.x [XR&CO'2014], Thu, 09 Jul 2020 20:43:21 GMT -->
</html>
b IDATxytVսϓ22 A@IR:hCiZ[v*E:WũZA ^dQeQ @ !jZ'>gsV仿$|?g)&x-E