HEX
Server: Apache/2.4.59 (Debian)
System: Linux skycube.cz 4.19.0-25-amd64 #1 SMP Debian 4.19.289-2 (2023-08-08) x86_64
User: ilya (534)
PHP: 7.3.31-1~deb10u7
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: /var/www/ilya/data/www/afish-ka.ru/modules/services/weather_import.inc
<?

$file = "http://informer.gismeteo.ru/xml/32540_1.xml";
function trustedFile($file) {
    // only trust local files owned by ourselves
    if (!eregi("^([a-z]+)://", $file)
        && fileowner($file) == getmyuid()) {
            return true;
    }
    return false;
}

function startElement($parser, $name, $attribs) {
    GLOBAL $forecast,$phenomena,$pressure,$temperature,$wind,$relwet,$heat;
    $name = strtolower($name);
    if (sizeof($attribs)) {

        $temp = array();
        while (list($k, $v) = each($attribs)) {
        $k = strtolower($k);
                 $temp[$k] = $v;

        }
    $$name = $temp;
    
    }

}

function endElement($parser, $name) {
    GLOBAL $forecast,$phenomena,$pressure,$temperature,$wind,$relwet,$heat;
        print $forecast[0];

       /* foreach($FORECAST as $k => $v) {
   // print "\$a[$k] => $v.<br>";
}        */

        if ($name == "FORECAST")
            {
            $result = mysql_query("SELECT COUNT(`id`) FROM `weather` WHERE `datetime`='".$forecast['year']."-".$forecast['month']."-".$forecast['day']." ".$forecast['hour'].":00:00';");
            print $forecast['day']."-".$forecast['month']."-".$forecast['year'].": ";
            if (!$result)
                 print "Error\r\n";
            else
                {
                $result = mysql_fetch_array($result);
                if ($result[0]==0)
                    {
                    print "Add\r\n";
                    mysql_query("INSERT INTO `weather` VALUES ('','".$forecast['year']."-".$forecast['month']."-".$forecast['day']." ".$forecast['hour'].":00:00',".$phenomena['cloudiness'].",".$phenomena['precipitation'].",".$phenomena['rpower'].",".$phenomena['spower'].",".$pressure['max'].",".$pressure['min'].",".$temperature['max'].",".$temperature['min'].",".$wind['max'].",".$wind['min'].",".$wind['direction'].",".$relwet['max'].",".$relwet['min'].",".$heat['max'].",".$heat['min'].");");
                    }
                else
                    {
                    print "Update\r\n";
                    mysql_query("UPDATE `weather` SET `phenomena_cloudiness=`".$phenomena['cloudiness'].", `phenomena_precipitation`=".$phenomena['precipitation'].", `phenomena_rpower`=".$phenomena['rpower'].", `phenomena_spower`=".$phenomena['spower'].", `pressure_max`=".$pressure['max'].", `pressure_min`=".$pressure['min'].", `temperature_max`".$temperature['max'].", `temperature_min`=".$temperature['min'].", `wind_max`=".$wind['max'].", `wind_min`=".$wind['min'].", `wind_direction`=".$wind['direction'].", `relwet_max`=".$relwet['max'].", `relwet_min`=".$relwet['min'].", `heat_max`=".$heat['max'].", `heat_min`=".$heat['min']." WHERE `datetime`='".$forecast['year']."-".$forecast['month']."-".$forecast['day']." ".$forecast['hour'].":00:00' LIMIT 1;");
                    }
                }
            }

}

function characterData($parser, $data) {

}

function PIHandler($parser, $target, $data) {
    switch (strtolower($target)) {
        case "php":
            global $parser_file;
            // If the parsed document is "trusted", we say it is safe
            // to execute PHP code inside it.  If not, display the code
            // instead.
            if (trustedFile($parser_file[$parser])) {
                eval($data);
            } else {
                /*printf("Untrusted PHP code: <i>%s</i>",
                        htmlspecialchars($data));*/
            }
            break;
    }
}

function defaultHandler($parser, $data) {
    if (substr($data, 0, 1) == "&" && substr($data, -1, 1) == ";") {
        /*printf('<font color="#aa00aa">%s</font>',
                htmlspecialchars($data));*/
    } else {
        /*printf('<font size="-1">%s</font>',
                htmlspecialchars($data));*/
    }
}

function externalEntityRefHandler($parser, $openEntityNames, $base, $systemId,
                                  $publicId) {
    if ($systemId) {
        if (!list($parser, $fp) = new_xml_parser($systemId)) {
            /*printf("Could not open entity %s at %s\n", $openEntityNames,
                   $systemId);*/
            return false;
        }
        while ($data = fread($fp, 4096)) {
            if (!xml_parse($parser, $data, feof($fp))) {
                /*printf("XML error: %s at line %d while parsing entity %s\n",
                       xml_error_string(xml_get_error_code($parser)),
                       xml_get_current_line_number($parser), $openEntityNames);*/
                xml_parser_free($parser);
                return false;
            }
        }
        xml_parser_free($parser);
        return true;
    }
    return false;
}


function new_xml_parser($file) {
    global $parser_file;

    $xml_parser = xml_parser_create();
    xml_parser_set_option($xml_parser, XML_OPTION_CASE_FOLDING, 1);
    xml_set_element_handler($xml_parser, "startElement", "endElement");
    xml_set_character_data_handler($xml_parser, "characterData");
    xml_set_processing_instruction_handler($xml_parser, "PIHandler");
    xml_set_default_handler($xml_parser, "defaultHandler");
    xml_set_external_entity_ref_handler($xml_parser, "externalEntityRefHandler");

    if (!($fp = @fopen($file, "r"))) {
        return false;
    }
    if (!is_array($parser_file)) {
        settype($parser_file, "array");
    }
    $parser_file[$xml_parser] = $file;
    return array($xml_parser, $fp);
}

if (!(list($xml_parser, $fp) = new_xml_parser($file))) {
    die("could not open XML input");
}


while ($data = fread($fp, 4096)) {
    if (!xml_parse($xml_parser, $data, feof($fp))) {
        die(sprintf("XML error: %s at line %d\n",
                    xml_error_string(xml_get_error_code($xml_parser)),
                    xml_get_current_line_number($xml_parser)));
    }
}


xml_parser_free($xml_parser);

?>