403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)eizo.hkosl.com/global/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)eizo.hkosl.com/global/webadmin/model_modifyform.php
<?php
	include 'config.php';

	// Check if the user is logged in

	if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1')) {
		header("Location: login.php");
		exit;
	}

	$model_id = (int)$_GET["model_id"];

	$sth1 = $dbh->prepare("SELECT * FROM model model, series series WHERE model.series_id = series.series_id and model_id=? ");
	$parameter = array($model_id);
	if (!$sth1->execute($parameter))
		throw new Exception('[' . $sth1->errorCode() . ']: ' . print_r($sth1->errorInfo()));

	$row = $sth1->fetch(PDO::FETCH_ASSOC);

	$sql99 = "SELECT * FROM sys_cms_login WHERE cmsloginid=?";
	$sth99 = $dbh->prepare($sql99);
	$sth99->execute(array((int)$row{'lastupby'}));
	$row99 = $sth99->fetch(PDO::FETCH_ASSOC);


	//check if this model has been record for a warranty
	$sql = "select * from customer_warranty warranty, series series, model model where series.series_id = model.series_id and warranty.model_code = model.model_code and warranty.series_code = series.series_code and model.model_id = ? and warranty.deleted = ?";
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

	if (!$sth->execute(array($model_id, "0"))) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

	if($sth->rowCount() > 0){
		echo "<script>alert('This model already linked with some customer warranty. ');</script>";
	}
?>
<html>
<head>
	<link rel="stylesheet" type="text/css" href="css/style.css"/>
	<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
	<title>Content Management System (CMS) - Powered by One Solution Limited</title>

	<script src="//code.jquery.com/jquery-1.10.2.js"></script>
	<link rel="stylesheet" href="//code.jquery.com/ui/1.10.4/themes/smoothness/jquery-ui.css">
	<script src="//code.jquery.com/ui/1.10.4/jquery-ui.js"></script>

	<script type="text/javascript">
		$(function () {
			$("#promote_datefrom").datepicker({
				dateFormat: 'yy-mm-dd'
			});

			$("#promote_dateto").datepicker({
				dateFormat: 'yy-mm-dd'
			});

		});

	</script>
</head>
<body>

<form action="model_modify.php" method="post" name="modifyform" enctype="multipart/form-data">
	<input type="hidden" name="model_id" value="<?= $row{'model_id'}; ?>">
	<input type="hidden" name="series_code" value="<?= $_GET{'series_code'}; ?>">
	<table width="800" border="0" cellpadding="0" cellspacing="0">
		<tr>
			<td height="70" align="right" valign="middle" class="icontxt">
				<table border="0" cellpadding="0" cellspacing="0">
					<tr>
						<td width="50" align="center" style="font-size: 13px;">
							<input type="image" alt="submit" src="images/iconSave.png" width="32" height="32" border="0"><br> &nbsp;Save&nbsp;&nbsp;
						</td>
						<td width="50" align="center">
							<a href="model_index.php?region=<?=$row{"region"}?>&series_code=<?=$_GET["series_code"]?>&msg=Cancel"><img src="images/iconCancel.png" alt="Cancel" width="32" height="32" border="0"><br> &nbsp;Cancel&nbsp;&nbsp;
							</a></td>
						<td>&nbsp;</td>
					</tr>
				</table>
			</td>
		</tr>
		<tr>
			<td>
				<span style="float:left;" class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle"/> Modify: Product Model
					</b></span><span style="float:right;" class="msg">Last Update: <?= $row99{'cmsloginname'} . '&nbsp;&nbsp;&nbsp;' . $row{'lastupdate'}; ?></span>
			</td>
		</tr>
		<tr>
			<td align="left" valign="middle"><!-- Content -->
				<table border="0" cellpadding="0" cellspacing="0">

					<tr>
						<td width="180" align="right" valign="top" class='content'>Region</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<?=$row{"region"}?>

							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Series Code</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<?=$row{"series_code"}?>
							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Model Code</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<!--<input type="text" class="content" name="model_code" value="<?=$row{"model_code"}?>" maxlength="100" />-->
							<?=$row{"model_code"}?>

							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Fixed Warranty Year</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<input type="text" class="content" name="fixed_warranty_year" value="<?=$row{"fixed_warranty_year"}?>"/>
							<br><br>
						</td>
					</tr>





					<tr>
						<td width="180" align="right" valign="top" class='content'>Promote Date from</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content' >
							<input type="text" class="content" name="promote_datefrom" value="<?=$row{"promote_datefrom"}?>" id="promote_datefrom" maxlength="100"/>

							to <input type="text" class="content" name="promote_dateto" value="<?=$row{"promote_dateto"}?>" id="promote_dateto" maxlength="100" />
							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Free On-site Calibration</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<select name="free_mix_color">
								<option value="0" <?php if($row{"free_mix_color"} == "0") echo "selected"; ?>>N/A</option>
								<option value="1" <?php if($row{"free_mix_color"} == "1") echo "selected"; ?>>Yes</option>
							</select>
							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Extend Warranty Months</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<input type="text" class="content" name="extend_warranty_year" value="<?=$row{"extend_warranty_year"}?>"/>
							<br><br>
						</td>
					</tr>


					<?php
						foreach ($arraylangcode as $langcode => $langname) {
							if($row{"region"} == "HK" && $langcode == "sc"){
								continue;
							}

							if($row{"region"} == "CN" && $langcode == "tc"){
								continue;
							}
					?>
						<tr>
							<td width="180" align="right" valign="top" class='content'>Warranty Detail<br>[<?=$langname?>]</td>
							<td class='content' valign="top">:&nbsp;</td>
							<td class='content'>
								<textarea name="warranty_detail_<?=$langcode?>" style="width:400px; height: 150px;"><?=$row{"warranty_detail_".$langcode}?></textarea>

								<br><br>
							</td>
						</tr>
					<?php } ?>

					<?php
						foreach ($arraylangcode as $langcode => $langname) {
							if($row{"region"} == "HK" && $langcode == "sc"){
								continue;
							}

							if($row{"region"} == "CN" && $langcode == "tc"){
								continue;
							}
						?>
						<tr>
							<td width="180" align="right" valign="top" class='content'>Warranty Detail Extend <br>[<?=$langname?>]</td>
							<td class='content' valign="top">:&nbsp;</td>
							<td class='content'>
								<textarea name="warranty_detail_extend_<?=$langcode?>" style="width:400px; height: 150px;"><?=$row{"warranty_detail_extend_".$langcode}?></textarea>

								<br><br>
							</td>
						</tr>
					<?php } ?>

				</table>
			</td>
		</tr>
	</table>
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit