403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/survey_demo/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/survey_demo/webadmin/basic_info.php
<?php
	require_once('configure.php');


	if (!function_exists('escape_string')) {
		function escape_string($data)
		{

			//return ($data);

			$replacements = array(
				//"'" => '&#039;',
				//'"' => '&quot;',
				//"\\" => '\\\\',
			);
			return strtr($data, $replacements);
		}
	}

	if (!function_exists('bind_pdo')) {
		function bind_pdo($sql, $parameters = NULL, $action = NULL)
		{
			global $dbh;

			if ($action == "insert" || $action == "update" || $action == "delete" || empty($action)) {
				if (!($sth = $dbh->prepare($sql))) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				}

				if (!$sth->execute($parameters)) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				} else {
					return true;
				}
			}

			if ($action == "selectone") {
				if (!($sth = $dbh->prepare($sql))) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				}

				if (!$sth->execute($parameters)) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				}

				$result = $sth->fetch(PDO::FETCH_ASSOC);
				if (!empty($result)) {
					foreach ($result as $key => $row) {
						$result[$key] = escape_string($result[$key]);
					}
				}

				return $result;

			}

			if ($action == "selectall") {
				if (!($sth = $dbh->prepare($sql))) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				}

				if (!$sth->execute($parameters)) {
					throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
				}

				$result = $sth->fetchAll(PDO::FETCH_ASSOC);
				if (!empty($result)) {
					foreach ($result as $key => $row) {
						foreach ($row as $key2 => $row2) {
							$result[$key][$key2] = escape_string($result[$key][$key2]);
						}
					}
				}

				return $result;

			}

			if ($action == "dump") {
				return dump_sql($sql, $parameters);
			}


		}
	}


	if (!function_exists('dump_sql')) {
		function dump_sql($sql, $parameters)
		{
			$keys = array();

			# build a regular expression for each parameter
			foreach ($parameters as $key => $value) {
				/*if (is_string($key)) {
					$keys[] = '/:' . $key . '/';
				} else {
					$keys[] = '/[?]/';
				}*/

				$keys[] = '/[?]/';
			}

			foreach ($parameters as $key2 => $value) {
				$parameters[$key2] = "'" . $value . "'";
			}

			$sql = preg_replace($keys, $parameters, $sql, 1, $count);

			#trigger_error('replaced '.$count.' keys');

			return $sql;
		}
	}

	$sql           = "SELECT * FROM sys_lang WHERE langstatus = 1 ORDER BY langsort ASC ";
	$sys_lang_info = bind_pdo($sql, NULL, "selectall");
	foreach ($sys_lang_info as $sys_lang) {
		$arraylangcode[$sys_lang['langcode']] = $sys_lang['langname'];
	}


	//functions

	if (!function_exists('random_string')) {
		function random_string($length = 8)
		{
			$chars         = "abcdefghijkmnpqrstuvwxyzABCDEFGHIJKLMNPQRSTUVWXYZ23456789abcdefghijkmnpqrstuvwxyzABCDEFGHIJKLMNPQRSTUVWXYZ23456789";
			$random_string = substr(str_shuffle($chars), 0, $length);
			return $random_string;
		}
	}

	if (!function_exists('aes_crypt')) {
		function aes_crypt($data, $encrypt_decrypt)
		{

			/*set_include_path(get_include_path() . PATH_SEPARATOR . 'phpseclib0.3.8');
			include('Net/SSH2.php');
			include('Crypt/RSA.php');*/

			set_include_path(get_include_path() . PATH_SEPARATOR . 'phpseclib1.0.1');

			if (!class_exists('Crypt_AES')) {
				include_once('phpseclib1.0.1/Crypt/AES.php');
			}

			$aes_crypt = new Crypt_AES();

			$key = '9m+RYPPR-H3^d@drJMpNk-GTxfV^KyAWs#Cb8cMsNW9Zf#$L8$hB5w$jH7UnGb#asDg-m%VSgfuh8KG$p8F-9J%78fH*x@Dgu_uFD?KTxPEg9hr7-XUxpz6jx8FmLJdB#VSD?Lk?MGDbdQdaeXUb@ytE9v*jS&LLfAYLv=Wr&YpnQS3dKVUVj3n*xJYUvSmpNN?juK^$3Sp-a43NQBj$Xbhtr7-h_g4ujz@6s-*sZPHB%cSYZk_vDm59q@REF?wF';

			$aes_crypt->setKey($key);

			if ($encrypt_decrypt == 1) {
				if (!empty($data)) {
					return base64_encode($aes_crypt->encrypt($data));
				} else {
					return;
				}
			}

			if ($encrypt_decrypt == 2) {
				if (!empty($data)) {
					return $aes_crypt->decrypt(base64_decode($data));
				} else {
					return;
				}
			}
		}
	}


	function matched_option($data1, $data2, $type)
	{
		if ($data1 == $data2) {
			if ($type == "checkbox" || $type == "radiobutton") {
				return "checked";
			} else if ($type == "select") {
				return "selected";
			} else {
			}

		}
	}

	if (!function_exists('startsWith')) {
		function startsWith($haystack, $needle)
		{
			$length = strlen($needle);
			return (substr($haystack, 0, $length) === $needle);
		}
	}

	if (!function_exists('check_upload_path')) {
		function check_upload_path($img_file)
		{
			$session_path_str  = "/uploader/" . $_SESSION['KCFINDER']['uploadURL'];
			$session_path_long = strlen($session_path_str);
			$path_error        = 0;
			foreach ($img_file as $key2 => $pathname) {
				if ($key2 && $pathname) {
					$submit_path_str  = substr($pathname, 0, $session_path_long);
					$submit_path_long = strlen($submit_path_str);
					$file             = str_replace('..', '', $pathname);
					if ($session_path_long <> $submit_path_long || $session_path_str <> $submit_path_str || !startsWith($file, $session_path_str)) {
						$path_error = 1;
					}
				}
			}
		}
	}


	if (!function_exists('validateDate')) {
		function validateDate($date, $format = 'Y-m-d H:i:s')
		{
			if (is_string($date)) {
				$d = DateTime::createFromFormat($format, $date);
				return $d && $d->format($format) == $date;
			} else {
				return false;
			}
		}
	}


	if (!function_exists('insert_record')) {
		function insert_record($table_name, $data, $dump_sql = NULL)
		{
			$result = "";

			if (!empty($table_name) && !empty($data)) {
				$sql        = "insert into `" . $table_name . "` set ";
				$parameters = array();
				foreach ($data as $table_field => $value) {
					$sql .= "`" . $table_field . "` = ?, ";
					$parameters[] = $value;
				}

				$sql = substr_replace($sql, "", -2);
			}

			if (!empty($dump_sql)) {
				$result = dump_sql($sql, $parameters);
			} else {
				$result = bind_pdo($sql, $parameters);
			}

			return $result;
		}
	}

	if (!function_exists('update_record')) {
		function update_record($table_name, $data, $where, $dump_sql = NULL)
		{
			$result = "";

			if (!empty($table_name) && !empty($data)) {
				$sql        = "update `" . $table_name . "` set ";
				$parameters = array();
				foreach ($data as $table_field => $value) {
					$sql .= "`" . $table_field . "` = ?, ";
					$parameters[] = $value;
				}
				$sql = substr_replace($sql, "", -2);

				$sql .= " where " . $where["sql"];
				foreach ($where["parameters"] as $table_field => $value) {
					$parameters[] = $value;
				}

				if (!empty($dump_sql)) {
					$result = dump_sql($sql, $parameters);
				} else {
					$result = bind_pdo($sql, $parameters);
				}

			}

			return $result;
		}
	}


	if (!function_exists('call_curl')) {
		function call_curl($url, $postData, $post)
		{
			if (!empty($post)) {
				$ch = curl_init();
				curl_setopt($ch, CURLOPT_URL, $url);
				curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
				curl_setopt($ch, CURLOPT_POST, 1);
				curl_setopt($ch, CURLOPT_IPRESOLVE, CURL_IPRESOLVE_V4);
				curl_setopt($ch, CURLOPT_HEADER, 0);
				curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
				curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);
				$result = curl_exec($ch);
				curl_close($ch);
			} else {
				$ch = curl_init();
				curl_setopt($ch, CURLOPT_URL, $url);
				curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
				curl_setopt($ch, CURLOPT_IPRESOLVE, CURL_IPRESOLVE_V4);
				curl_setopt($ch, CURLOPT_HEADER, 0);
				curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
				$result = curl_exec($ch);
				curl_close($ch);
			}

			return $result;
		}
	}


	if (!function_exists('numberformat')) {
		function numberformat($data, $decial_place = 2, $thousand = ",")
		{
			return number_format($data, $decial_place, ".", $thousand);
		}
	}

	/*if (!function_exists('_log')) {
		function _log($page, $log_id, $log_sql, $log_para)
		{
			$data = array(
				"page"       => $page,
				"log_id"     => $log_id,
				"log_sql"    => $log_sql,
				"log_para"   => json_encode($log_para),
				"log_query"  => dump_sql($log_sql, $log_para),
				"createdate" => date("Y-m-d H:i:s"),
			);

			insert_record("log", $data);

		}
	}*/

	if (!function_exists('get_master_type_code')) {
		function get_master_type_code($typeid, $code = NULL)
		{
			if (!empty($code)) {
				$sql        = "select * from master_type_code where typeid = ? and code = ? and deleted = ? order by name_en ASC";
				$parameters = array($typeid, $code, 0);
				$result     = bind_pdo($sql, $parameters, "selectone");
			} else {
				$sql        = "select * from master_type_code where typeid = ? and deleted = ? order by name_en ASC";
				$parameters = array($typeid, 0);
				$result     = bind_pdo($sql, $parameters, "selectall");
			}

			return $result;
		}
	}

	if (!function_exists('get_campaign')) {
		function get_campaign($id = null, $deleted = 0)
		{
			$sql        = "select * from campaign where deleted = ?";
			$parameters = array($deleted);

			if (!empty($id)) {
				$sql .= " and id = ?";
				$parameters[] = $id;
			}

			$sql .= " order by start_date DESC";

			if (!empty($id)) {
				$result = bind_pdo($sql, $parameters, "selectone");
			} else {
				$result = bind_pdo($sql, $parameters, "selectall");
			}

			return $result;
		}
	}


	if (!function_exists('fn_parse_form_data')) {
		function fn_parse_form_data($xml)
		{
			$fields = array();
			$xml    = simplexml_load_string($xml);
			$xml    = $xml->fields;

			if (isset($xml->field)) {
				foreach ($xml->children() as $field) {
					$name          = (string)trim($field['name']);
					$fields[$name] = array();

					foreach ($field->attributes() as $k => $v) {
						$fields[$name][$k] = (string)trim($v);
					}

					if (!empty($field->option)) {
						foreach ($field->option as $k => $v) {
							$fields[$name]["option"]["label"][] = (string)trim($v);
							$fields[$name]["option"]["value"][] = (string)trim($v["value"]);
						}
					}
				}
			}
			return $fields;
		}
	}

	if (!function_exists('get_question')) {
		function get_question($campaign_id)
		{
			$sql        = "select * from question where campaign_id = ? and deleted = ? order by sort ASC";
			$parameters = array($campaign_id, 0);
			$result     = bind_pdo($sql, $parameters, "selectall");

			return $result;
		}
	}

	if (!function_exists('check_user_has_fill_form')) {
		function check_user_has_fill_form($campaign_id, $vip_code=null)
		{
			//check if user has fill form or not
			if(empty($vip_code)){
				$sql        = "select * from answer where campaign_id = ? and session_id = ? and deleted = ? and temp = ?";
				$parameters = array($campaign_id, session_id(), 0, 0);
			}else{
				$sql        = "select * from answer where campaign_id = ? and vip_code = ? and deleted = ? and temp = ?";
				$parameters = array($campaign_id, $vip_code, 0, 0);
			}

			$result     = bind_pdo($sql, $parameters, "selectone");

			if (!empty($result)) {
				echo "<script type='text/javascript'>alert('You have completed our survey before. Thanks you very much.\\n你之前已完成問卷。多謝參與'); location.href='campaign.php?id=" . $campaign_id . "'</script>";
				exit;
			}
		}
	}

	if (!function_exists('check_campaign_date')) {
		function check_campaign_date($campaign)
		{
			$nowdate = date("Y-m-d H:i:s");
			$valid = true;
			if($nowdate < $campaign["start_date"]){
				$valid = false;
				echo "<script type='text/javascript'>alert('The start date of this campaign is ".$campaign["start_date"].".\\n活動開始日期是 ".$campaign["start_date"]."。');</script>";
			}

			if($nowdate > $campaign["end_date"]." 23:59:59"){
				$valid = false;
				echo "<script type='text/javascript'>alert('This campaign is finished.\\n這個活動已完結。');</script>";
			}

			if(!$valid){
				if (strpos($_SERVER['REQUEST_URI'], "campaign.php") === FALSE){
					header("Location: campaign.php?id=".$campaign["id"]);
				}
			}
		}
	}

	if (!function_exists('check_image_resolution')) {
		function check_image_resolution($image)
		{
			list($width, $height, $type, $attr) = getimagesize($image);

			if ($width <= 2500 && $height <= 2500) {
				return true;
			} else {
				return false;
			}
		}
	}


	if (isset($_GET["msg"]) && (int)$_GET["msg"] == $_GET["msg"]) {
		$msg_master_info = get_master_type_code("WEBADMIN", $_GET["msg"]);
		if (!empty($msg_master_info)) {
			$msg = $msg_master_info["name_en"];
		} else {
			//$msg = $_GET["msg"];
		}
	}

	$sql        = "SELECT * FROM site_info WHERE siteinfoid = ? ";
	$parameters = array(1);
	$row0       = bind_pdo($sql, $parameters, "selectone");
	$site_info  = $row0;

Youez - 2016 - github.com/yon3zu
LinuXploit