403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)eizo.hkosl.com/global/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)eizo.hkosl.com/global/webadmin/serial_number_modifyform.php
<?php
	include 'config.php';

	// Check if the user is logged in

	if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1')) {
		header("Location: login.php");
		exit;
	}

	$serial_number_id = (int)$_GET["serial_number_id"];

	$sql1 = "SELECT * FROM serial_number where serial_number_id=? ";
	if (!($sth1 = $dbh->prepare($sql1))) {
		throw new Exception('[' . $sth1->errorCode() . ']: ' . print_r($sth1->errorInfo()));
	}

	if (!$sth1->execute(array($serial_number_id))) {
		throw new Exception('[' . $sth1->errorCode() . ']: ' . print_r($sth1->errorInfo()));
	}

	$row1 = $sth1 -> fetch(PDO::FETCH_ASSOC);
	$series_code = $row1{"series_code"};
	$region = $row1{"region"};
	$model_code = $row1{"model_code"};
	$serial_number = $row1{"serial_number"};

	$sql99 = "SELECT * FROM sys_cms_login WHERE cmsloginid=?";
	$sth99 = $dbh->prepare($sql99);
	$sth99->execute(array((int)$row1{'lastupby'}));
	$row99 = $sth99->fetch(PDO::FETCH_ASSOC);

	//check if this model has been record for a warranty
	$sql = "select * from customer_warranty warranty, series series, model model where series.series_id = model.series_id and warranty.model_code = model.model_code and warranty.series_code = series.series_code and warranty.serial_number = ? and warranty.region = ? and warranty.series_code =? and warranty.model_code=? and warranty.deleted = ?";
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

	if (!$sth->execute(array($serial_number, $region, $series_code, $model_code, "0"))) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

	if($sth->rowCount() > 0){
		echo "<script>alert('This serial number already linked with some customer warranty.');</script>";
	}
?>
<html>
<head>
	<link rel="stylesheet" type="text/css" href="css/style.css"/>
	<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
	<title>Content Management System (CMS) - Powered by One Solution Limited</title>

	<script type="text/javascript" src="js/jquery-1.7.1.min.js"></script>
	<link rel="stylesheet" href="//code.jquery.com/ui/1.10.4/themes/smoothness/jquery-ui.css">
	<script src="//code.jquery.com/jquery-1.10.2.js"></script>
	<script src="//code.jquery.com/ui/1.10.4/jquery-ui.js"></script>
	<script type="text/javascript" src="js/jquery.chained.min.js" ></script>
	<script type="text/javascript">
		$(function(){
			$("#model").chained("#series");
		});
	</script>
</head>
<body>

<form action="serial_number_modify.php" method="post" name="modifyform" enctype="multipart/form-data">
	<input type="hidden" name="serial_number_id" value="<?= $row{'serial_number_id'}; ?>">
	<table width="800" border="0" cellpadding="0" cellspacing="0">
		<tr>
			<td height="70" align="right" valign="middle" class="icontxt">
				<table border="0" cellpadding="0" cellspacing="0">
					<tr>
						<td width="50" align="center">
							<input type="image" alt="submit" src="images/iconSave.png" width="32" height="32" border="0"><br> &nbsp;Save&nbsp;&nbsp;
						</td>
						<td width="50" align="center">
							<a href="serial_number_index.php?msg=Cancel"><img src="images/iconCancel.png" alt="Cancel" width="32" height="32" border="0"><br> &nbsp;Cancel&nbsp;&nbsp;
							</a></td>
						<td>&nbsp;</td>
					</tr>
				</table>
			</td>
		</tr>
		<tr>
			<td>
				<span style="float:left;" class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle"/> Modify: Product Serail Number
					</b></span><span style="float:right;" class="msg">Last Update: <?= $row99{'cmsloginname'} . '&nbsp;&nbsp;&nbsp;' . $row1{'lastupdate'}; ?></span>
			</td>
		</tr>
		<tr>
			<td align="left" valign="middle"><!-- Content -->
				<table border="0" cellpadding="0" cellspacing="0">

					<tr>
						<td width="180" align="right" valign="top" class='content'>Series Code</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<select name="series_id" id="series">
								<?php
									$sql = "SELECT * FROM series where deleted = ? ORDER BY series_code ASC ";
									if (!($sth = $dbh->prepare($sql))) {
										throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
									}

									if (!$sth->execute(array("0"))) {
										throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
									}

									while ($row = $sth->fetch(PDO::FETCH_ASSOC)) {
										if($series_code == $row{"series_code"} && $region == $row{"region"}){
											$this_selected = "selected";
										}else{
											$this_selected = "";
										}
										echo '<option value="'.$row{"series_id"}.'" '.$this_selected.'>'.$row{"series_code"}.' ('.$row{"region"}.')</option>';
									}
								?>
							</select>
							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Model Code</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<select id="model" name="model_code" required>

								<?php
									$sql = "select * from model model, series series where model.series_id = series.series_id and model.status = ? and model.deleted = ? and series.status = ? and series.deleted = ? order by series.series_code ASC, model.model_code ASC";

									if (!($sth = $dbh->prepare($sql))) {
										throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
									}

									if (!$sth->execute(array("1", "0", "1", "0"))) {
										throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
									}

									$all_model = $sth->fetchAll();

									foreach ($all_model as $model) {
										if($model_code == $model{"model_code"} && $series_code == $model["series_code"] && $region == $model{"region"}){
											$this_selected = "selected";
										}else{
											$this_selected = "";
										}

										echo '<option value="' . $model["model_code"] . '" class="' . $model["series_id"] . '" '.$this_selected.'>' . $model["model_code"] . '</option>';
									}

								?>

							</select>
							<br><br>
						</td>
					</tr>

					<tr>
						<td width="180" align="right" valign="top" class='content'>Serial Number</td>
						<td class='content' valign="top">:&nbsp;</td>
						<td class='content'>
							<input type="text" name="serial_number" value="<?=$serial_number?>" style="width: 250px;" />
							<br><br>
						</td>
					</tr>

				</table>
			</td>
		</tr>
	</table>
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit